Nextcloud Security: Integrating Proxy Protocol (HAproxy L4) #4438
-
Hello, First of all, I would like to thank everyone who worked on this project. This project is truly incredible. I have a layer 4 reverse proxy (HAProxy) and I wonder if it's possible to add in line 4 of the nextcloud.conf file of Apache (RemoteIPProxyProtocol On) because otherwise Nextcloud doesn't recognize the real IP address of the clients. Or maybe a small checkbox in the main container, because I understand that it's a potential vulnerability if, for example, a client manages to send a custom TCP packet directly to Apache, but for me, it's on an isolated network. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Thank you! Hi, I don't know if it is that easy to simply do RemoteIPProxyProtocol On since caddy always sits between apache and external reverse proxies. Maybe this would need to be enabled in caddy as well? Some help on this is appreciated :) |
Beta Was this translation helpful? Give feedback.
Thank you!☺️
Hi, I don't know if it is that easy to simply do RemoteIPProxyProtocol On since caddy always sits between apache and external reverse proxies. Maybe this would need to be enabled in caddy as well?
Some help on this is appreciated :)