# 4. Setup

<div align="right">

![logo](https://docs.tic.gal/uploads/images/gallery/2026-08/nAetR7YT24RohlNC-embedded-image-a8o32zki.png)

</div>

*Part of the **More Security** manual — see also [1. Introduction](https://docs.tic.gal/books/more-security/page/1-introduction), [2. What's New](https://docs.tic.gal/books/more-security/page/2-whats-new), [3. Scope](https://docs.tic.gal/books/more-security/page/3-scope), [5. Usage](https://docs.tic.gal/books/more-security/page/5-usage), [6. Troubleshooting](https://docs.tic.gal/books/more-security/page/6-troubleshooting).*

## 4.1 Installation

Install like any GLPI plugin: from the GLPI Marketplace, or by downloading it and installing/activating it from **Setup > Plugins**.

## 4.2 Configuration

Configuration lives entirely on the **More Security** tab of **Setup > General** — no separate setup wizard. See the manual's [3. Usage](03-usage.md) chapter for the full walkthrough with screenshots.

### 4.2.1 Automatic actions

- Monthly automatic update of the GeoIP database for geoblocking
- Weekly automatic cleanup of old, resolved security-log entries

A scheduled task runs automatically (once a month) to download the latest DB-IP Lite database, keeping geoblocking country data current.

Another scheduled task runs automatically (roughly once a week, overnight) to clean up old, resolved entries from the security log, so the log doesn't grow forever. Only entries that are no longer blocking anyone are removed; anything still actively blocked — including a permanent block — is kept. How long an entry is kept before cleanup is configurable from **Setup > Automatic actions**.

Actually blocking and unblocking happens instantly when an attempt occurs — only the log cleanup and database updates run on a schedule.

## 4.3 Permissions

- Changing the More Security settings requires the same permission as changing any other general GLPI setting — no separate right to manage.
- Viewing the security log is controlled by its own dedicated permission, which can be given to specific profiles independently of other rights. This log is read-only for everyone: even a profile with full rights can view entries but never edit or delete them.
- The trusted-network whitelist is configured alongside other settings in the More Security configuration tab, using the same permission as other general GLPI settings.

## 4.4 Configuring More Security

The More Security plugin provides brute-force protection for login and password-reset attempts, with per-account and per-IP throttling. All configuration is done through one tab in Setup > General.

### 4.4.1 Open the More Security configuration

From GLPI's main menu, navigate to **Setup > General** and click the **More Security** tab to access the plugin's configuration interface.

![The More Security tab shows all protection settings organized into sections for IP blocking, Login attempts, and Password reset.](https://docs.tic.gal/uploads/images/gallery/2026-08/NuUcMIzq5EEaRVFy-embedded-image-zuwjpgta.png)

*The More Security tab shows all protection settings organized into sections for IP blocking, Login attempts, and Password reset.*

> **Note:** All configuration changes take effect immediately without requiring a page reload or GLPI restart.

### 4.4.2 Configure login attempt blocking

The **Login attempts** section defines how many failed logins trigger a temporary account block, and how long that block lasts. In this example: after 5 failed attempts, the account is locked for 300 seconds.

![Login attempts are configured to block accounts after 5 failed login attempts, for 300 seconds.](https://docs.tic.gal/uploads/images/gallery/2026-08/0PegJBZfvAjTKjdz-embedded-image-7zmww0al.png)

*Login attempts are configured to block accounts after 5 failed login attempts, for 300 seconds.*

### 4.4.3 Set password reset attempt limits

The **Password reset** section prevents unauthorized account takeover through reset-link brute-forcing, with its own independent attempt limit and block duration. In this example: after 3 failed reset attempts, access is locked for 600 seconds.

![Password reset is limited to 3 attempts per 600 seconds to prevent reset-link abuse.](https://docs.tic.gal/uploads/images/gallery/2026-08/2FNdB8yGMslG8cPa-embedded-image-utbujtou.png)

*Password reset is limited to 3 attempts per 600 seconds to prevent reset-link abuse.*

### 4.4.4 Configure IP-based blocking and trusted proxies

The **IP blocking** section throttles abuse by source IP — shared across login and password-reset attempts — independent of the per-account limits above, plus distributed-attack detection and trusted reverse-proxy IPs.

![The IP blocking section configures per-IP attempt limits, distributed-attack detection, and trusted reverse-proxy IPs.](https://docs.tic.gal/uploads/images/gallery/2026-08/SpanVuWo3tFcg3jL-embedded-image-nie1pdv3.png)

*The IP blocking section configures per-IP attempt limits, distributed-attack detection, and trusted reverse-proxy IPs.*

### 4.4.5 Review currently blocked accounts

Below the configuration fields, the **Active blocks** table lists every account, IP, or email currently locked, with the attempt count and remaining block time. Individual rows (or a selection) can be unlocked early. In this example, the account `testuser` shows as temporarily blocked.

![The Active blocks table shows every currently locked account, IP, or email, with its expiration and an Unlock action.](https://docs.tic.gal/uploads/images/gallery/2026-08/WQIcRl1yjFlXQ5z4-embedded-image-ltzuszwq.png)

*The Active blocks table shows every currently locked account, IP, or email, with its expiration and an Unlock action.*

### 4.4.6 Configure the IP whitelist and trusted proxies

The **Whitelisting** section exempts trusted networks from IP-based blocking entirely, and separately lists reverse proxies whose own IP should be ignored in favour of the forwarded client address. **Whitelisted IPs/CIDR ranges** accepts one or more comma-separated CIDR ranges (e.g. `192.0.2.0/24`) or single addresses — any login or password-reset attempt from a whitelisted address bypasses all IP-based limits and geoblocking. In this example: `192.0.2.0/24` is whitelisted.

![The Whitelisting section exempts `192.0.2.0/24` from IP-based blocking and geoblocking.](https://docs.tic.gal/uploads/images/gallery/2026-08/SanXlK9HTPsX1vHT-embedded-image-3g1hfwgw.png)

*The Whitelisting section exempts `192.0.2.0/24` from IP-based blocking and geoblocking.*

### 4.4.7 Configure geoblocking by country

The **Geoblocking** section restricts logins by the country the client IP resolves to: disabled, allow-list only, or block-list. Whitelisted IPs and unresolvable IPs (private/local, or a missing database) always bypass this check.

![The Geoblocking section sets the allow/deny mode and the country list it applies to, with the DB-IP data attribution.](https://docs.tic.gal/uploads/images/gallery/2026-08/SpJdkoU3vUmERRDQ-embedded-image-4avhuurs.png)

*The Geoblocking section sets the allow/deny mode and the country list it applies to, with the DB-IP data attribution.*

> **Note:** Geoblocking country data comes from DB-IP's free Lite database, refreshed automatically once a month.

> Generated for **More Security 2.0.0** on GLPI 11.0.8 — 2026-08-24.