# Reverse Proxy (nginx-proxy-manager) & Crowdsec IP Ban

**URL:** https://community.letsencrypt.org/t/reverse-proxy-nginx-proxy-manager-crowdsec-ip-ban/220504
**Category:** Help
**Created:** [June 21, 2024, 7:26pm UTC](https://community.letsencrypt.org/t/reverse-proxy-nginx-proxy-manager-crowdsec-ip-ban/220504 "2024-06-21T19:26:08Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Kein](https://avatars.discourse-cdn.com/v4/letter/k/e79b87/32.png) [@Kein](https://community.letsencrypt.org/u/Kein)
#### Post date: [June 21, 2024, 7:26pm UTC](https://community.letsencrypt.org/t/reverse-proxy-nginx-proxy-manager-crowdsec-ip-ban/220504/1 "2024-06-21T19:26:08Z")

</div>

My domain is: [kein.go.ro](http://kein.go.ro/)

Hi! I'm trying to have nginx-proxy-manager block certain IPs after a given amount of failed login attempts for obvious reasons. I'm running things in container using Portainer to be exact (with the help of stacks). Here's a docker compose file I run for both nginx-proxy-manage & crowdsec:

```nohighlight
version: '3.8'

services:
  nginx-reverse-proxy:
    image: 'jc21/nginx-proxy-manager:latest'
    container_name: nginx-reverse-proxy
    restart: unless-stopped
    ports:
      - '42393:80' # Public HTTP Port
      - '42345:443' # Public HTTPS Port
      - '78521:81' # Admin Web Port
    volumes:
      - ./data:/data
      - ./letsencrypt:/etc/letsencrypt
      - ./data/logs/nginx:/var/log/nginx # Montează jurnalul de acces al Nginx

  crowdsec:
    image: crowdsecurity/crowdsec:latest
    container_name: crowdsec
    restart: unless-stopped
    volumes:
      - ./data/backup/Nginx/crowdsec:/etc/crowdsec
      - /var/run/docker.sock:/var/run/docker.sock

    networks:
      - crowdsec-network
    cap_add:
      - SYS_PTRACE
    environment:
      - TZ=UTC

networks:
  crowdsec-network:
    driver: bridge

```

My OS: Ubuntu 23.10 (GNU/Linux 6.5.0-41-generic x86\_64)

The issue that I'm facing particularly is with nginx-logs.yaml, can't get it right somehow:

```nohighlight
name. crowdsecurity/nginx-logs
description: "Parse Nginx access and error logs"
filter: "evt.Meta.service == 'http' && evt.Meta.log_type in ['http_access-log', 'http_error-log']"
grok:
  patterns:
    - 'NGINX_ACCESS %{IPORHOST:client_ip} - %{DATA:ident} %{DATA:auth} \[%{HTTPDATE:timestamp}\] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:http_version})?|%{DATA})" %{NUMBER:response} (?:%{NUMBER:bytes}|-) %{QS:referrer} %{QS:agent}'
    - 'NGINX_ERROR \[%{HTTPDATE:timestamp}\] %{LOGLEVEL:level} %{DATA:pid}#%{NUMBER}: \*%{NUMBER}: %{GREEDYDATA:message}, client: %{IPORHOST:client_ip}, server: %{DATA:server}, request: "%{DATA:request}", host: "%{DATA:host}"'

```

log file reads

```nohighlight
cofiguration file '/etc/crowdsec/parsers/s02-enrich/nginx-logs.yaml': yaml: unmarshal errors:\n line 6: field on_success not found in type parser.Node". 

```

Hope this gives you a general idea. Thank you for the help.

---

<div class="post-metadata">

### Author: ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)
#### Post date: [June 21, 2024, 7:30pm UTC](https://community.letsencrypt.org/t/reverse-proxy-nginx-proxy-manager-crowdsec-ip-ban/220504/2 "2024-06-21T19:30:34Z")

</div>

I'm not really sure how this is related to Let's Encrypt certificates.

That looks like a problem better directed to the NPM support forum

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [June 21, 2024, 7:50pm UTC](https://community.letsencrypt.org/t/reverse-proxy-nginx-proxy-manager-crowdsec-ip-ban/220504/3 "2024-06-21T19:50:24Z")

</div>

I agree with Mike here. I can't see any relationship with Let's Encrypt, HTTPS, TLS or certificates.

I'm going to close this thread due to the above mentioned reason. If you think this is an error and your thread was actually related to Let's Encrypt/certificates, feel free to open a new thread. Please note that NPM is a terrible piece of software when it comes to ACME and certificates and without the complete log we usually can't do anything.

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [June 21, 2024, 7:50pm UTC](https://community.letsencrypt.org/t/reverse-proxy-nginx-proxy-manager-crowdsec-ip-ban/220504/4 "2024-06-21T19:50:27Z")

</div>


