1) yes
2) if unwanted traffic can be recognized by firewall, they can be blocked by the firewall first, before reaching litespeed. Litespeed can further filter traffic which has passed through firewall, and log the problem IPs in error.log. next, fail2ban can capture the problem IPs in...