# Docker / NPM and Firewall Bouncer

**URL:** <https://discourse.crowdsec.net/t/docker-npm-and-firewall-bouncer/1354>\
**Category:** crowdsec\
**Created:** [July 13, 2023, 4:00am UTC](https://discourse.crowdsec.net/t/docker-npm-and-firewall-bouncer/1354 "2023-07-13T04:00:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Xohelloes](https://avatars.discourse-cdn.com/v4/letter/x/ba8739/32.png) [@Xohelloes](https://discourse.crowdsec.net/u/Xohelloes)\
**Post date:** [July 13, 2023, 4:00am UTC](https://discourse.crowdsec.net/t/docker-npm-and-firewall-bouncer/1354/1 "2023-07-13T04:00:40Z")

</div>

Hello all. Maybe you can help a noob who is still learning out to configure Crowdsec

I run a few services in Docker. To make them accessible to the internet I manage them via Nginx Proxy Manager. My NPM also handles the ssl encryption. This way I can run multiple websites on my domain and seperate them by different subdomains.

I installed Crowdsec and the Firewall Bouncer. Fortunately it seems like it’s working for SSH ootb. Unfortunately it seems like it won’t block up addresses who try to brute force into my websites which are managed by NPM. Why is that? I assume Crowdsec can’t access and read my log files. So how do I fix that so the firewall Bouncer also blogs trying to brute force into those services?

The following services run on NPM and are exposed to the internet:

1. NPM
2. Portainer
3. Vaultwarden password manager

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [July 13, 2023, 3:29pm UTC](https://discourse.crowdsec.net/t/docker-npm-and-firewall-bouncer/1354/2 "2023-07-13T15:29:56Z")

</div>

Guessing you are same user on [reddit](https://www.reddit.com/r/CrowdSec/comments/14yau4f/protecting_my_docker_npm_and_websites/)

---

<div class="post-metadata">

**Author:** ![Xohelloes](https://avatars.discourse-cdn.com/v4/letter/x/ba8739/32.png) [@Xohelloes](https://discourse.crowdsec.net/u/Xohelloes)\
**Post date:** [July 13, 2023, 6:17pm UTC](https://discourse.crowdsec.net/t/docker-npm-and-firewall-bouncer/1354/3 "2023-07-13T18:17:44Z")

</div>

yeah I’m and I really struggle to protect my Vaultwarden service which is running on port 11000 and forwarded by Nginx Proxy Manager to receive a SSL cert.

Things I tried today:

setting the acquis.yml:

```auto
source: docker
container_name:
 - Vaultwarden
container_id:
 - b069df8e7b8d38a2e4ec1355b02c18668aa0e073ed743f4240177c03655e87bc
labels:
  type: vaultwarden

```

set the container log of vaultwarden:

```auto
filenames:
  - /var/lib/docker/volumes/vw-data/_data/vaultwarden.log
labels:
  type: vaultwaren

```

- modified my bouncer firewall settings to` disable ipv6, set the iptables chain to "DOCKER-USER"`.
- installed `https://hub.crowdsec.net/author/Dominic-Wagner/collections/vaultwarden`

I don’t know what else to do because it seems like it’s not working. Any ideas?

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [July 16, 2023, 11:18am UTC](https://discourse.crowdsec.net/t/docker-npm-and-firewall-bouncer/1354/4 "2023-07-16T11:18:35Z")

</div>

Can we please just centralise your communication to a single platform you opened a reddit, discourse and discord threads I reply on one and get no reply.

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [July 16, 2023, 11:19am UTC](https://discourse.crowdsec.net/t/docker-npm-and-firewall-bouncer/1354/5 "2023-07-16T11:19:20Z")

</div>

Locking thread here please go to your [discord thread](https://discord.com/channels/921520481163673640/1129251518378418187)

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [July 16, 2023, 11:19am UTC](https://discourse.crowdsec.net/t/docker-npm-and-firewall-bouncer/1354/6 "2023-07-16T11:19:27Z")

</div>


