What is the Security Settings to Use for Wordfence when website is under attack
-
Hi there.
A week ago my website was under attack, which brought down my site completely.
The attack prompted me to install wordfence.After installation, the attack lessened but it still brings my site down for a few hours every day. Currently xmlrpc.php is disabled so that my site can keep running.
What should the wordfence settings that should be used ? Can I enable xmlrpc.php again after changing the settings ?
Currently my settings are :
Brute Force Protection
Enforce strong passwords: Force admin to use strong password.
Lock out after how many login failures : 5
Lock out after how many forgot password attempt : 5
Count failures over what time period : 1 day
Amount of time a user is locked out : 60 Days
The remaining boxes for this section are checked.Rate Limiting :
Immediately block fake Google crawlers : this box is not checked.
How should we treat Google’s crawlers : unlimited access.
If anyone’s requests exceed 960 /mins then throttle it.
If a crawler’s page views exceed 960 /mins then throttle it.
If a crawler’s pages not found (404s) exceed 2240/min then throttle it.
If a human’s page views exceed unlimited then throttle it.
If a human’s pages not found (404s) exceed 120/min then throttle it.
If 404s for known vulnerable URLs exceed 30/min then throttle it.
How long is an IP address blocked when it breaks a rule : 1 Day.Thanks in advance for your help.
- The topic ‘What is the Security Settings to Use for Wordfence when website is under attack’ is closed to new replies.