Chris027 Posted June 26, 2023 Posted June 26, 2023 I just had a new member sign up and his/her registration IP address is showing a private address. I queried all my members to see if this has happened previously and I see nobody with this issue. Any idea how a private IP can be shown as the registration IP?
Randy Calvert Posted June 26, 2023 Posted June 26, 2023 (edited) Are you using a proxy, firewall, or a cdn or something else in front of the server? Edited June 26, 2023 by Randy Calvert
Chris027 Posted June 26, 2023 Author Posted June 26, 2023 1 minute ago, Randy Calvert said: Are you using a proxy, firewall, or a cdn or something else in front of the server? I use all kinds of stuff through CloudFlare and NGINX, but this has never happened previously. Other new users are showing public IPs, all existing users are showing public IPs.
Marc Posted June 27, 2023 Posted June 27, 2023 The only way that can really happen is if its being proxied in some way. Do you have the following switched on? System>Settings>Advanced Configuration>Check IP address when validating session?
Chris027 Posted June 27, 2023 Author Posted June 27, 2023 4 hours ago, Marc Stridgen said: The only way that can really happen is if its being proxied in some way. Do you have the following switched on? System>Settings>Advanced Configuration>Check IP address when validating session? Yes, this is enabled.
Marc Posted June 27, 2023 Posted June 27, 2023 Sorry, Chris. The setting above should have been "Trust IP addresses provided by proxies?"
Chris027 Posted June 27, 2023 Author Posted June 27, 2023 12 minutes ago, Marc Stridgen said: Sorry, Chris. The setting above should have been "Trust IP addresses provided by proxies?" Also enabled.
Marc Posted June 27, 2023 Posted June 27, 2023 As mentioned in the setting, it is actually possible for the IP to be spoofed when using that setting. Not always maliciously, I might add. When using that setting, its using the IP that is provided by the proxy, and therefore if that proxy is providing the wrong IP address, then the wrong IP will be shown Chris027 1
Recommended Posts