# Ban again unbanned ip-addresses

**URL:** <https://discourse.crowdsec.net/t/ban-again-unbanned-ip-addresses/833>\
**Category:** crowdsec\
**Created:** [June 1, 2022, 5:14pm UTC](https://discourse.crowdsec.net/t/ban-again-unbanned-ip-addresses/833 "2022-06-01T17:14:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![janbaer](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/janbaer/32/358_2.png) [@janbaer](https://discourse.crowdsec.net/u/janbaer)\
**Post date:** [June 1, 2022, 5:14pm UTC](https://discourse.crowdsec.net/t/ban-again-unbanned-ip-addresses/833/1 "2022-06-01T17:14:54Z")

</div>

For test reasons, I sent two requests which were captured by a scenario with type trigger. So after the first request I got a decision that the IP should be banned. The second request returned a 403, as expected, because the IP is banned.

To try another request with the same IP, I removed the decision for this IP. But now I could send a lot of such requests which caused a decision before.

Is there any explanation for this? Is the IP landed somehow on a whitelist because I removed it from the decisions?

---

<div class="post-metadata">

**Author:** ![blotus](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/blotus/32/109_2.png) [@blotus](https://discourse.crowdsec.net/u/blotus)\
**Post date:** [June 1, 2022, 9:50pm UTC](https://discourse.crowdsec.net/t/ban-again-unbanned-ip-addresses/833/2 "2022-06-01T21:50:46Z")

</div>

Hello,

This is probably because of the [blackhole parameter](https://docs.crowdsec.net/docs/next/scenarios/format/#blackhole) which prevents taking decisions on IPs that were banned a few moments ago (the value is different for each scenario, you can have a look at the scenarios themselves to see what the duration is).

---

<div class="post-metadata">

**Author:** ![janbaer](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/janbaer/32/358_2.png) [@janbaer](https://discourse.crowdsec.net/u/janbaer)\
**Post date:** [June 2, 2022, 10:06am UTC](https://discourse.crowdsec.net/t/ban-again-unbanned-ip-addresses/833/3 "2022-06-02T10:06:12Z")

</div>

@blotus Thanks, I can confirm that I had a blackhole of 5m configured. After 5 minutes I could block my self again 😉
