Safe deployment
Client IPs behind a proxy
Your application must see each visitor’s real address before you turn on IP blocking. Otherwise many visitors share the proxy’s address, and one ban hits them all.
Verify before blocking
- Add your management address to the product’s allowlist or
never_blocksetting. Keep hosting-console access available. - Configure the web server to accept client-address headers only from your known proxies. Restrict direct access to the origin when possible.
- Make a request from a separate connection and compare the address in your web-server log with Witen’s local activity.
- Send a forged forwarding header directly to the origin. It must not replace the real sender’s address.
- Enable blocking after both checks pass. Recheck after changing proxies, containers, or CDN settings.
WordPress and Cloudflare
By default, Witen starts with PHP’s REMOTE_ADDR. It accepts CF-Connecting-IP with a Cloudflare request marker when the direct peer is in its recognized Cloudflare ranges. By default, a Cloudflare header from any other peer is ignored.
For nginx, Apache, or another load balancer, configure the server’s real-IP module with the exact trusted proxy ranges so PHP receives the visitor in REMOTE_ADDR. If a local proxy sits between Cloudflare and PHP, configure that proxy to validate Cloudflare first.
Witen ignores X-Forwarded-For. The legacy witen_trusted_proxy_headers option explicitly trusts selected headers globally; it does not restrict them to a configured peer range. Use it only when the origin accepts requests exclusively through a proxy that overwrites those headers. Where you can, resolve the address in the web server instead. If the plugin shows a proxy warning, check the host configuration.
Use Recover login access if an existing rule has blocked your proxy.
Matomo
Witen uses Matomo’s resolved HTTP sender address. Configure Matomo’s trusted proxy addresses and client-IP header for your network, then verify both ordinary requests and tracker requests. The plugin adds no forwarding-header trust rules of its own.
Keep the Matomo origin restricted to the proxies you configured, and check a direct request with a forged header before enabling IP rules.
Warden log sources and containers
Make sure each selected log source records the real client. Container sources default to the peer address and observation-only enforcement. Enable trusted-proxy parsing only for proxies you control:
client_ip_mode = "trusted_proxy"
trusted_proxy_cidrs = ["172.20.0.10/32", "2001:db8:20::10/128"]Use your actual proxy ranges in the container source configuration. Warden never bans those trusted proxy ranges. Stay in observation-only mode while you check the address Warden picks, and turn on host blocking only once it is right.
Continue with the Warden configuration guide.