fail2ban proxmox webgui with nginx reverse proxy

cybermcm

Well-Known Member
Aug 20, 2017
101
10
58
I've setup a mail gateway 5.0-71 solution with a nginx reverse proxy one the same machine (using let's encrypt certificates). Everything works.
Now I want to setup fail2ban to add a security layer (web GUI is currently reachable via Internet).
Problem: In every logfile (daemon.log, syslog, pmgproxy.log) there is only 127.0.0.1 as source ip listed.

Is there a way to log the real client ip?

Thanks for any help in advance.
 
Why do you want to setup fail2ban and why to use a nginx reverse proxy? You can use certs also without nginx and if you want this acme thing doing with let's encrypt thing, there are explanations here to do so. For your web GUI look at my advancing thread and use a firewall to limit access to particular IP addresses or use my explanations to install OpenVPN, so the machine is only accessible via OpenVPN. It's easy and much safer than wait for hackers to fail2ban them.
 
Thanks for your reply and yes a firewall / OpenVPN are far more safe than fail2ban. Nevertheless I just want to know if it is possible to create a fail2ban filter for this setup...
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!