# Wrong client IP when Vaultwarden is behind a reverse proxy

**URL:** <https://vaultwarden.discourse.group/t/wrong-client-ip-when-vaultwarden-is-behind-a-reverse-proxy/3028>\
**Category:** Uncategorized\
**Created:** [October 23, 2023, 9:18pm UTC](https://vaultwarden.discourse.group/t/wrong-client-ip-when-vaultwarden-is-behind-a-reverse-proxy/3028 "2023-10-23T21:18:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dactyl](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/dactyl/32/1205_2.png) [@dactyl](https://vaultwarden.discourse.group/u/dactyl)\
**Post date:** [October 23, 2023, 9:18pm UTC](https://vaultwarden.discourse.group/t/wrong-client-ip-when-vaultwarden-is-behind-a-reverse-proxy/3028/1 "2023-10-23T21:18:52Z")

</div>

I’m running my VW instance behind a reverse proxy that manages SSL certificates and access restrictions. The proxy sends through X-Forwarded-For header, but there doesn’t seem to be a way to configure VW for a list of trusted proxies that it should listen to that header for.

Not sure if this is a feature request or something I’m missing in the configuration.

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [October 23, 2023, 9:50pm UTC](https://vaultwarden.discourse.group/t/wrong-client-ip-when-vaultwarden-is-behind-a-reverse-proxy/3028/2 "2023-10-23T21:50:01Z")

</div>

The latter, you need to provide the right headers.

> <https://github.com/dani-garcia/vaultwarden/blob/ecb31c85d68202f9d215c8ce12939158fb858af9/.env.template#L59..L61>

---

<div class="post-metadata">

**Author:** ![dactyl](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/dactyl/32/1205_2.png) [@dactyl](https://vaultwarden.discourse.group/u/dactyl)\
**Post date:** [October 23, 2023, 11:14pm UTC](https://vaultwarden.discourse.group/t/wrong-client-ip-when-vaultwarden-is-behind-a-reverse-proxy/3028/3 "2023-10-23T23:14:32Z")

</div>

Awesome, thank you for the quick reply! I was able to add that env variable and have it all working as expected now.

---

<div class="post-metadata">

**Author:** ![MatthewMartin11](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@MatthewMartin11](https://vaultwarden.discourse.group/u/MatthewMartin11)\
**Post date:** [October 27, 2023, 12:37am UTC](https://vaultwarden.discourse.group/t/wrong-client-ip-when-vaultwarden-is-behind-a-reverse-proxy/3028/4 "2023-10-27T00:37:04Z")

</div>

Add the following line to config.json configuration file:  
“ip\_header”: “X-Forwarded-For”,

---

<div class="post-metadata">

**Author:** ![ShadowPulse](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/shadowpulse/32/1237_2.png) [@ShadowPulse](https://vaultwarden.discourse.group/u/ShadowPulse)\
**Post date:** [December 8, 2023, 2:54pm UTC](https://vaultwarden.discourse.group/t/wrong-client-ip-when-vaultwarden-is-behind-a-reverse-proxy/3028/5 "2023-12-08T14:54:57Z")

</div>

What will this line change?
