Question about Caddy & Caddy Bouncer
I'm trying to use https://github.com/hslatman/caddy-crowdsec-bouncer with my caddyfile in order to block malicious IPs, however when I attempted to block my own IP (for testing purposes) I was still able to access the site. Am I doing something wrong?
I also have the caddy logs parser as well https://app.crowdsec.net/hub/author/crowdsecurity/log-parsers/caddy-logs and I also added Cloudflares IPs under trusted_proxies and it does show my IP correctly in the caddy log under
X-Forwarded-For so I'm not sure as to why IPs aren't being blocked.
I also ran tail /var/log/caddy/caddy.log | head -n 20 | cscli explain -f- --type caddy -v and it did indicate it was able to parse the log, I can provide a log file of it in DMs if need be
GitHub
GitHub - hslatman/caddy-crowdsec-bouncer: A Caddy module that block...
A Caddy module that blocks malicious traffic based on decisions made by CrowdSec. - hslatman/caddy-crowdsec-bouncer
Collections, AppSec Rules & Configurations | CrowdSec Hub
Manage collections, configurations, remediation components, and AppSec rules with CrowdSec Hub. Streamline security with tools and integrations for enhanced protection.
4 Replies
Important Information
This post has been marked as resolved. If this is a mistake please press the red button below or type
/unresolve© Created By WhyAydan for CrowdSec ❤️
bump
bump as this is still not resolved
Since you set the trusted proxies within the reverse proxy struct, I guess its not happening at the right time?
so crowdsec and appsec trigger before and therefore the IP will be cloudflares.
there a global configuration option afaik https://caddyserver.com/docs/caddyfile/options#trusted-proxies
but dont use caddy at all, so its guess work from my side.
Resolving Question about Caddy & Caddy Bouncer
This has now been resolved. If you think this is a mistake please run
/unresolve