If a session already has valid creds, simply don't penalize it. You can still penalize new logins from that IP if you really want to, but I wouldn't recommend it, because that way anyone who can spoof bad logins from that IP can DOS the service at little effort.