# Fail2Ban + Docker Compose

**URL:** <https://vaultwarden.discourse.group/t/fail2ban-docker-compose/1629>\
**Category:** Help\
**Created:** [May 16, 2022, 3:32am UTC](https://vaultwarden.discourse.group/t/fail2ban-docker-compose/1629 "2022-05-16T03:32:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![btipton](https://avatars.discourse-cdn.com/v4/letter/b/edb3f5/32.png) [@btipton](https://vaultwarden.discourse.group/u/btipton)\
**Post date:** [May 16, 2022, 3:32am UTC](https://vaultwarden.discourse.group/t/fail2ban-docker-compose/1629/1 "2022-05-16T03:32:36Z")

</div>

I currently have a stack that I am trying to implement a local installation of fail2ban with [Vaultwarden w/MariaDB + Caddy (All 3 Docker Compose)]. I am having trouble figuring out jail.d configurations whether or not I should replace

```auto
banaction = %(banaction_allports)s

```

with something else since my instance is running running behind the caddy proxy.  
Per the wiki.

```auto
NOTE:
Do not use this if you use a reverse proxy before Docker container. If proxy, like apache2 or nginx is used, use the ports of the proxy and do not use chain=FORWARD, only when using Docker without proxy!

NOTE on the NOTE above:
That's at least not true for running on Docker (CentOS 7) with caddy as reverse proxy. chain=FORWARD is absolutely fine and working with caddy as reverse proxy.

```

Anyone know if I should be doing something different other than the below due to the NOTE on the NOTE.

```auto
action = iptables-allports[name=vaultwarden, chain=FORWARD]

```

Any help is appreciated.  
Thanks

---

<div class="post-metadata">

**Author:** ![bokkabonga](https://avatars.discourse-cdn.com/v4/letter/b/f19dbf/32.png) [@bokkabonga](https://vaultwarden.discourse.group/u/bokkabonga)\
**Post date:** [May 16, 2022, 8:21am UTC](https://vaultwarden.discourse.group/t/fail2ban-docker-compose/1629/2 "2022-05-16T08:21:56Z")

</div>

Hey,

I am running a similar setup. Only Difference is, that i use a non-docker apache as a reverse proxy. For me the following works like a charm:

```auto
action = iptables-allports[name=bitwarden, chain=FORWARD]
         %(action_mw)s[from=*redacted*, destination=*redacted*, sendername=Fail2Ban]

```
