fake: The exceptions are granted only for IPs not explicitly refused
If we mark them as explicitly rejected or dropped by an IPset from the server-side blacklists, then don't let it in. We don't need to test if the IP is attacker, we already know that.
Please register or sign in to comment