{"id":19001598,"date":"2026-08-24T15:55:53","date_gmt":"2026-08-24T15:55:53","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/cannot-update-firewall-rules-behind-reverse-proxy\/"},"modified":"2026-08-24T15:55:53","modified_gmt":"2026-08-24T15:55:53","slug":"cannot-update-firewall-rules-behind-reverse-proxy","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/cannot-update-firewall-rules-behind-reverse-proxy\/","title":{"rendered":"Cannot update firewall rules behind reverse-proxy"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hello,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I am stuck in making Wordfence firewall update its rules. I manage a server in a University with complex networking (VLANs, http proxies and reverse-proxies). I tried many settings in the &#8220;General Wordfence Options&#8221; &gt; &#8220;How does Wordfence get IPs&#8221;, the correct setting being &#8220;X-Forwarded-For&#8221; according to me. I &#8220;trusted&#8221; our reverse-proxies, too. The &#8220;Diagnostics&#8221; tool shows success for an IPv4 &#8220;Connectivity&#8221;, and shows failure for an IPv6 one (which normally shouldn&#8217;t block the process, as long as IPv4 works)\u00b9. It is also noticed in the &#8220;IP Detection&#8221; section, that the X-Forwarded-For is &#8220;Configured but not valid&#8221;. Though, it shows my client IP correctly (which is a local network address).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I can&#8217;t get anything interesting in the WordPress and system logs, even in DEBUG mode.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other plugins, including Wordfence, and WordPress itself do auto-updates well. I think rules update never worked on that machine, since its installation, in June 2024.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u00b9 wp_remote_post() test back to this server failed<br \/>Response was: cURL error 7: Failed to connect to hashtag-infos.fr port 443 after 1 ms:<br \/>Could not connect to server<\/p>\n","protected":false},"template":"","class_list":["post-19001598","topic","type-topic","status-publish","hentry","topic-tag-firewall-rules","topic-tag-proxy","topic-tag-reverse-proxy"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19001598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19001598\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19001598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}