If you need more control, I'd advise to disable the default autoblock feature, and instead install the fail2ban contrib. It'll still ban offenders, but only after failed auth attempts, you can manage a whitelist of hosts/network which will never been banned, and it'll also monitor other services (http, imap, ftp etc...)