Enable PAM Brute‑Force Protection & IP Whitelisting in Imunify360
Learn how to enable Imunify360 PAM brute‑force protection and add IP whitelists on Ubuntu/Debian and AlmaLinux/Rocky servers with step‑by‑step commands.
5 min read
Imunify360 is a popular security suite for Linux web servers. Its PAM brute‑force protection module monitors the Pluggable Authentication Modules (PAM) stack and blocks repeated login attempts, while IP whitelisting guarantees that trusted addresses can always reach the server, even when strict firewall rules are applied. This guide shows how to enable both features on a typical AtoZNode VPS or dedicated server.
1. Prerequisites and Overview
Before you begin, ensure you have:
Root or sudo access.
Imunify360 installed and active (verify with imunify360-agent status).
A list of IP addresses you want to whitelist (office network, monitoring services, VPN, etc.).
Imunify360 integrates directly with the system’s PAM stack, so once the module is enabled it will automatically track failed authentication attempts and temporarily block the offending IP. The whitelist is applied at the firewall level (iptables or nftables) and is respected by the brute‑force module.
2. Enabling PAM Brute‑Force Protection
Ubuntu / Debian (APT)
# Refresh the local package index (optional but recommended)
apt update
# Install the Imunify360 PAM integration package
apt install imunify360-pam
# Enable PAM brute‑force protection
imunify360-agent config set pam_brute_force_protection enabled
# Restart the Imunify360 daemon to apply the change
systemctl restart imunify360
What each command does:
apt update – updates the local list of available packages.
apt install imunify360-pam – installs the PAM module for Imunify360.
imunify360-agent config set pam_brute_force_protection enabled – tells Imunify360 to start monitoring PAM login attempts.
systemctl restart imunify360 – reloads the daemon so the new setting takes effect.
AlmaLinux / Rocky Linux / RHEL (DNF)
# Update the repository metadata
dnf makecache
# Install the Imunify360 PAM integration package
dnf install imunify360-pam
# Enable PAM brute‑force protection
imunify360-agent config set pam_brute_force_protection enabled
# Restart the Imunify360 service
systemctl restart imunify360
The commands perform the same actions as the APT version, using the dnf package manager native to these distributions.
3. Configuring IP Whitelisting
Whitelisting is handled through Imunify360’s firewall rules. You can add single IPs, CIDR blocks, or entire subnets.
Add a Single IP (All Distributions)
# Replace 203.0.113.45 with the address you want to trust
imunify360-agent firewall whitelist add 203.0.113.45
This command creates a rule that always allows traffic from the specified address, regardless of other firewall actions.
Use CIDR notation when you need to trust an entire network (office, data‑center, VPN, etc.).
Persisting Whitelists Across Reboots
Imunify360 stores whitelist entries in its own configuration, so they survive reboots automatically. To view the current list at any time:
imunify360-agent firewall whitelist list
4. Verifying That Protection Is Active
After enabling PAM protection and adding whitelist entries, run a few checks to confirm everything works as expected.
Check PAM Module Status
imunify360-agent config get pam_brute_force_protection
The output should be enabled. If it shows disabled, repeat the enable step and ensure there are no typographical errors.
Review Active Firewall Rules
iptables -L -n | grep IMUNIFY360
On systems that use nftables instead of iptables, run:
nft list chain inet filter INPUT
Look for rules that reference IMUNIFY360 and the IPs you added to the whitelist.
Test the Whitelist
From a trusted machine, attempt an SSH login. Even after deliberately entering an incorrect password three times, the connection should remain allowed because the source IP is whitelisted. Then try a failed login from a non‑whitelisted address to confirm that the block is applied.
5. Fine‑Tuning Brute‑Force Parameters (Optional)
Imunify360 allows you to adjust how aggressively it reacts to failed attempts. The defaults work for most environments, but you can modify them to match your traffic patterns.
Adjust the Failure Threshold
# Set the number of allowed failures before a block (default is 5)
imunify360-agent config set pam_brute_force_protection.max_attempts 3
Set Block Duration
# Block the offending IP for 30 minutes (1800 seconds)
imunify360-agent config set pam_brute_force_protection.block_time 1800
After changing any parameter, restart the daemon:
systemctl restart imunify360
6. Best Practices for Ongoing Security
Keep Imunify360 updated. Run apt upgrade imunify360-agent or dnf upgrade imunify360-agent regularly.
Monitor the audit log. Imunify360 writes events to /var/log/imunify360/agent.log. Review it weekly for unusual activity.
Use strong passwords and SSH keys. Brute‑force protection is an additional layer, not a replacement for good authentication practices.
Document whitelist changes. Keep a simple text file with dates and reasons for each added IP; this aids audits and troubleshooting.
Test after major updates. Kernel or PAM updates can reset configuration files, so verify that protection remains enabled after system upgrades.
Conclusion
Enabling PAM brute‑force protection and configuring IP whitelisting in Imunify360 provides a solid defense against credential‑stuffing attacks while ensuring that trusted administrators and services retain uninterrupted access. The steps above cover both Debian/Ubuntu (APT) and AlmaLinux/Rocky/RHEL (DNF) environments, making it straightforward to apply the same hardening on any AtoZNode server. Regularly review logs, keep the software up‑to‑date, and maintain a clear whitelist policy to keep your web applications running securely.