# IP Header Not Match

**URL:** <https://vaultwarden.discourse.group/t/ip-header-not-match/1233>\
**Category:** Help\
**Created:** [October 28, 2021, 3:48pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233 "2021-10-28T15:48:38Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![skyfay](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@skyfay](https://vaultwarden.discourse.group/u/skyfay)\
**Post date:** [October 28, 2021, 3:48pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/1 "2021-10-28T15:48:38Z")

</div>

Hello, my dears.  
I have a small problem.  
When I log in via Bitwarden Web, I get an email that I have logged in.  
The problem is the IP is wrong it always takes: 172.17.0.1  
I use docker with an Apache Reverse Proxy …  
In the diagnostics there is IP header No Match.

 ![image](https://global.discourse-cdn.com/free1/uploads/vaultwarden/original/1X/3506ce2e860ac5b75e512e43e741b8aa086e19eb.png)

Would be cool if someone could help me.  
Thanks!

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [October 28, 2021, 5:37pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/2 "2021-10-28T17:37:52Z")

</div>

Either configure Apache to use `X-Real-IP` or configure Vaultwarden to use `X-Forwarded-For`.  
Also see [Proxy examples · dani-garcia/vaultwarden Wiki · GitHub](https://github.com/dani-garcia/vaultwarden/wiki/Proxy-examples)

---

<div class="post-metadata">

**Author:** ![skyfay](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@skyfay](https://vaultwarden.discourse.group/u/skyfay)\
**Post date:** [October 28, 2021, 6:30pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/3 "2021-10-28T18:30:00Z")

</div>

Thanks for the quick help.  
It worked for me.  
But, it shows wrong public IP addresses.  
The server is behind the Cloudflare proxy. Could it be that the IP of Cloudflare is taken instead of that of the user?

---

<div class="post-metadata">

**Author:** ![jjlin](https://avatars.discourse-cdn.com/v4/letter/j/e19adc/32.png) [@jjlin](https://vaultwarden.discourse.group/u/jjlin)\
**Post date:** [October 28, 2021, 9:20pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/4 "2021-10-28T21:20:30Z")

</div>

With Cloudflare you need to use `X-Forwarded-For` or `CF-Connecting-IP`:

[https://support.cloudflare.com/hc/en-us/articles/200170986-How-does-Cloudflare-handle-HTTP-Request-headers-](https://support.cloudflare.com/hc/en-us/articles/200170986-How-does-Cloudflare-handle-HTTP-Request-headers-)

---

<div class="post-metadata">

**Author:** ![skyfay](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@skyfay](https://vaultwarden.discourse.group/u/skyfay)\
**Post date:** [October 29, 2021, 11:26am UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/5 "2021-10-29T11:26:26Z")

</div>

Could you help me a little further?  
I have now installed the “mod\_cloudflare”.  
I ran the “sudo a2enmod remoteip” command.  
I also made this:

 ![image](https://global.discourse-cdn.com/free1/uploads/vaultwarden/original/1X/04be7aeadcec1dd4ed0570eb9ced391fc9f38d25.png)

How do i have to edit my reverse proxy configuration now?  
With X-Real-IP it looked like this:

```auto
<VirtualHost *:80>
ServerName domain.com
Redirect permanent / https://domain.com/
</VirtualHost>
<VirtualHost *:443>
   ServerName domain.com
   SSLEngine On
   ProxyPreserveHost On
   SSLCertificateFile /etc/letsencrypt/live/domain.com/fullchain.pem
   SSLCertificateKeyFile /etc/letsencrypt/live/domain.com/privkey.pem
   ProxyPass / http://127.0.0.1:xy/
   ProxyPassReverse / 127.0.0.1:xy/
   ProxyPreserveHost On
   ProxyRequests Off
   RequestHeader set X-Real-IP %{REMOTE_ADDR}s
</VirtualHost>

```

Without X-Real-IP it looks like this:

```auto
<VirtualHost *:80>
ServerName domain.com
Redirect permanent / https://domain.com/
</VirtualHost>
<VirtualHost *:443>
   ServerName domain.com
   SSLEngine On
   ProxyPreserveHost On
   SSLCertificateFile /etc/letsencrypt/live/domain.com/fullchain.pem
   SSLCertificateKeyFile /etc/letsencrypt/live/domain.com/privkey.pem
   ProxyPass / http://127.0.0.1:xy/
   ProxyPassReverse / 127.0.0.1:xy/
</VirtualHost>

```

How do i have to edit this code to use the CF-Connecting-IP ?

---

<div class="post-metadata">

**Author:** ![jjlin](https://avatars.discourse-cdn.com/v4/letter/j/e19adc/32.png) [@jjlin](https://vaultwarden.discourse.group/u/jjlin)\
**Post date:** [October 29, 2021, 6:19pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/6 "2021-10-29T18:19:56Z")

</div>

You don’t need to do anything in the Apache config. Just go to the admin page and set `Client IP header` (ip\_header config item) to either `X-Forwarded-For` or `CF-Connecting-IP`.

See

> **[Configuration overview · dani-garcia/vaultwarden Wiki](https://github.com/dani-garcia/vaultwarden/wiki/Configuration-overview)**
>
> Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden\_rs - Configuration overview · dani-garcia/vaultwarden Wiki

> <https://github.com/dani-garcia/vaultwarden/blob/a2316ca091ebb7f6e4ed06d150d72474ef103839/.env.template#L41>

---

<div class="post-metadata">

**Author:** ![skyfay](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@skyfay](https://vaultwarden.discourse.group/u/skyfay)\
**Post date:** [October 29, 2021, 9:41pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/7 "2021-10-29T21:41:10Z")

</div>

Done. I tried both one but always header not match and the IP is every time 172.17.0.1…

 ![image](https://global.discourse-cdn.com/free1/uploads/vaultwarden/original/1X/a6b2ea134041eaacae21da0eaca2c495c1361c58.png)  
What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![skyfay](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@skyfay](https://vaultwarden.discourse.group/u/skyfay)\
**Post date:** [October 29, 2021, 9:42pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/8 "2021-10-29T21:42:02Z")

</div>

And here the other one:

 ![image](https://global.discourse-cdn.com/free1/uploads/vaultwarden/original/1X/feb62072b903f96821855939647c3d0b1277d1ba.png)  
I can’t post two pictures in one post…

---

<div class="post-metadata">

**Author:** ![jjlin](https://avatars.discourse-cdn.com/v4/letter/j/e19adc/32.png) [@jjlin](https://vaultwarden.discourse.group/u/jjlin)\
**Post date:** [October 29, 2021, 10:12pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/9 "2021-10-29T22:12:11Z")

</div>

> [@skyfay](#):
>
> Done. I tried both one but always header not match and the IP is every time 172.17.0.1…
> 
> ![image](https://global.discourse-cdn.com/free1/uploads/vaultwarden/original/1X/a6b2ea134041eaacae21da0eaca2c495c1361c58.png)  
> What am I doing wrong?

This should not happen unless you have trailing whitespace in your config. Ideally we should trim it automatically, but I don’t think that’s done currently.

---

<div class="post-metadata">

**Author:** ![jjlin](https://avatars.discourse-cdn.com/v4/letter/j/e19adc/32.png) [@jjlin](https://vaultwarden.discourse.group/u/jjlin)\
**Post date:** [October 29, 2021, 10:13pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/10 "2021-10-29T22:13:37Z")

</div>

> [@skyfay](#):
>
> And here the other one:
> 
> ![image](https://global.discourse-cdn.com/free1/uploads/vaultwarden/original/1X/feb62072b903f96821855939647c3d0b1277d1ba.png)  
> I can’t post two pictures in one post…

Cloudflare should always be inserting `CF-Connecting-IP` automatically, so you may have some module or other configuration in Apache that is stripping that header.

---

<div class="post-metadata">

**Author:** ![skyfay](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@skyfay](https://vaultwarden.discourse.group/u/skyfay)\
**Post date:** [October 30, 2021, 1:53pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/11 "2021-10-30T13:53:23Z")

</div>

Finaly:

 ![image](https://global.discourse-cdn.com/free1/uploads/vaultwarden/original/1X/ca5a5be39edc23f35e9140ca2aba363b5286aab6.png)  
Thanks a lot guys for your help!

---

<div class="post-metadata">

**Author:** ![Trophy8747](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/trophy8747/32/1106_2.png) [@Trophy8747](https://vaultwarden.discourse.group/u/Trophy8747)\
**Post date:** [June 10, 2023, 8:48pm UTC](https://vaultwarden.discourse.group/t/ip-header-not-match/1233/12 "2023-06-10T20:48:30Z")

</div>

> [@jjlin](#):
>
> You don’t need to do anything in the Apache config. Just go to the admin page and set `Client IP header` (ip\_header config item) to either `X-Forwarded-For` or `CF-Connecting-IP`.

Thank you! This helped me.
