# Ban not working at all

**URL:** <https://discourse.crowdsec.net/t/ban-not-working-at-all/1311>\
**Category:** Uncategorized\
**Created:** [May 31, 2023, 7:18am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311 "2023-05-31T07:18:39Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![fvsadem](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/fvsadem/32/457_2.png) [@fvsadem](https://discourse.crowdsec.net/u/fvsadem)\
**Post date:** [May 31, 2023, 7:18am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311/1 "2023-05-31T07:18:40Z")

</div>

Hi,

It seems that, the ban action doesn’t work at all…

I have activated “duration\_expr” default option to rise the ban time everytime an ip is remediate.

 ![Capture d’écran du 2023-05-31 09-05-07](https://europe1.discourse-cdn.com/flex013/uploads/crowdsec/original/1X/448014616014b7eff8c225cff6c64b8f9f3b1ace.png)

In the image, you will see that the same ip is banned 4 times in 4h.  
Is this a normal behavior ?  
I expect to have no new notifications for this ip for 8 hours (the first time was two detections ago).

is the ip really ban or not ?

Thanks

---

<div class="post-metadata">

**Author:** ![fvsadem](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/fvsadem/32/457_2.png) [@fvsadem](https://discourse.crowdsec.net/u/fvsadem)\
**Post date:** [May 31, 2023, 7:40am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311/2 "2023-05-31T07:40:17Z")

</div>

Well,

If i check `cscli decisions list`

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/crowdsec/original/1X/025f6f7d9f3b65554cf78a4969e93025d9d75afb.png)

We see that the ip seems banned and the expiration time seems OK.

My question is more functionnal :  
If the ip is already banned why would i have more notifications ?

For me, it’s like it doesn’t work what ever if you activate the “duration\_time” or not, you receive multiple notifications.

Maybe if we could change the message by `<IP> try another time to trigger <trigger>, it will get ban for next <hours>h`.  
Is it possible to have differents messages ?

Thanks

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [June 1, 2023, 7:28am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311/3 "2023-06-01T07:28:34Z")

</div>

Which bouncers are you using? If it just nginx then the request still gets logged by nginx so it can multple trigger (it just means they get a 401 response code).

If you are using just the firewall bouncer are you using cloudflare? if so this bypasses the firewall bouncer as the firewall can only see cloudflare IP not the layer 7 IP in the header.

---

<div class="post-metadata">

**Author:** ![fvsadem](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/fvsadem/32/457_2.png) [@fvsadem](https://discourse.crowdsec.net/u/fvsadem)\
**Post date:** [June 1, 2023, 8:09am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311/4 "2023-06-01T08:09:05Z")

</div>

Hi @iiAmLoz,

I use Traefik Bouncer.

> **[GitHub - maxlerebourg/crowdsec-bouncer-traefik-plugin: Traefik plugin to...](https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin)**
>
> Traefik plugin to apply crowdsec decisions from local API - GitHub - maxlerebourg/crowdsec-bouncer-traefik-plugin: Traefik plugin to apply crowdsec decisions from local API

I check the log file and there is a lot of 404 for this IP (no 401). It stop logging this IP at 9h13 the 31 May.

```auto
...
79.124.59.162 - - [31/May/2023:09:12:27 +0000] "GET /web/sendgrid.env HTTP/1.1" 404 19 "-" "-" 3206450 "-" "-" 0ms
79.124.59.162 - - [31/May/2023:09:12:36 +0000] "GET /ADMIN/sendgrid.env HTTP/1.1" 404 19 "-" "-" 3206467 "-" "-" 0ms
79.124.59.162 - - [31/May/2023:09:12:45 +0000] "GET /api/sendgrid.env HTTP/1.1" 404 19 "-" "-" 3206477 "-" "-" 0ms
79.124.59.162 - - [31/May/2023:09:12:54 +0000] "GET /API/sendgrid.env HTTP/1.1" 404 19 "-" "-" 3206485 "-" "-" 0ms
79.124.59.162 - - [31/May/2023:09:13:03 +0000] "GET /apps/api/sendgrid.env HTTP/1.1" 404 19 "-" "-" 3206493 "-" "-" 0ms

```

First notification / decision the 30 May at 23h45

 ![image](https://europe1.discourse-cdn.com/flex013/uploads/crowdsec/original/1X/1737f0e937ae1efbb09a90f10a5ca4398a29ebc7.png)  
Last notification / decision the 31 May at 11h08

So it seems that the IP wasn’t block even if the decision has been made.  
Really i don’t understand what’s going on !

PS: I found nothing in auth.log or syslog.

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [June 1, 2023, 8:12am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311/5 "2023-06-01T08:12:45Z")

</div>

Hey,

I would check the plugin is working and communicating to the LAPI. You can ensure this by running `cscli bouncers list` unfortunately I cant really help with the bouncer since it is third party.

---

<div class="post-metadata">

**Author:** ![fvsadem](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/fvsadem/32/457_2.png) [@fvsadem](https://discourse.crowdsec.net/u/fvsadem)\
**Post date:** [June 1, 2023, 8:16am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311/6 "2023-06-01T08:16:43Z")

</div>

@iiAmLoz, traefik bouncer seems to work and communicate with LAPI.

`traefik-bouncer 172.18.0.2 ✔️ 2023-06-01T08:12:40Z Go-http-client 1.1 api-key`

The last sync was made today…

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [June 1, 2023, 8:22am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311/7 "2023-06-01T08:22:31Z")

</div>

Then all I can recommend is to look at the documentation for the bouncer, something doesn’t seem right. I haven’t used it so I dont have any ideas.

---

<div class="post-metadata">

**Author:** ![LuminatiHD](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/luminatihd/32/802_2.png) [@LuminatiHD](https://discourse.crowdsec.net/u/LuminatiHD)\
**Post date:** [June 24, 2024, 7:37am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311/8 "2024-06-24T07:37:30Z")

</div>

Hello, I’m facing the almost exact same problem, but with the normal firewall bouncers. I can confirm that the bouncers do pull the decisions.  
I did notice that the crowdsesc ban ipset gets basically cleared habitually, with no logs of the firewall bouncers indicating anything wrong happening.

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [June 24, 2024, 7:39am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311/9 "2024-06-24T07:39:22Z")

</div>

The IPSet get wiped OR does the rule get flushed from `iptables`?

---

<div class="post-metadata">

**Author:** ![LuminatiHD](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/luminatihd/32/802_2.png) [@LuminatiHD](https://discourse.crowdsec.net/u/LuminatiHD)\
**Post date:** [June 24, 2024, 7:48am UTC](https://discourse.crowdsec.net/t/ban-not-working-at-all/1311/10 "2024-06-24T07:48:45Z")

</div>

We observed this phenomenon: when reloading the bouncer service, it pulls all the decisions and adds all banned IPs to the blocklist, like it should (about, say, 70 decisions). But after some time (can be a few seconds or a few minutes), something suddenly switches and the ipset contains only like 2 IPs.
