Well this might be an excellent idea. After 24 hours, with a much lower (3 sec) out of range time in the reject rule , I had no more “banned (last failure - not allowed by access-list)” messages !!!
So far the long out of range time in the reject rule seems to have triggered that banned condition.
Current setting: "Allow signal out of range " time for the authenticate rule (120..-86) is 30 sec, and 3 sec for the no-authenticate rule (-87..-120)
The test is only 24 hours young.