How long will the IP be blocked when getting secd.rpc.authRequest.blocked alert?
Applies to
- CIFS
- ONTAP 9
Answer
The client IP where failed logon attempts originated from will be blocked for one minute and will suppress the EMS to hourly.
Additional Information
- As per current ONTAP releases (February 2025), the duration of the block of 1 minute cannot be configured.
- Many secd.rpc.authRequest.blocked alerts after upgrading to 9.12+
- What is the threshold for "secd.rpc.authRequest.blocked"?
