Topic163 problems

Reverse Proxy Security

163 incident problems about Reverse Proxy Security. Start with the reviewed ones.

All problems (163)

NETWORK-1356A Cloudflare purge request returns success and one login page stays staleA page update is pushed urgently and later only one user segment continues to receive the stale login screen or policy page.NetworkIntermediate13 minProLINUX-1400A repo mirror is reachable and package installs failA repo mirror is reachable and package installs fail focuses on reverse-proxy-security and asks the reader to isolate the key signal in Linux. Package trust failures behind corporate proxies often live in the interception chain, not...LinuxAdvanced13 minProSECURITY-1344An NGINX auth_request chain protects the UI and one API path still bypasses policyA reverse proxy centralizes auth and later only API clients or browser preflight flows can reach one path without the expected policy check.SecurityIntermediate13 minProSECURITY-1333An NGINX auth_request chain works for browsers and fails for API clientsAn NGINX auth_request chain works for browsers and fails for API clients focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Authentication success at the edge does not preserve every authorization s...SecurityIntermediate13 minProNETWORK-1352An NGINX reverse proxy preserves client IP for the app and fail2ban still...An NGINX reverse proxy preserves client IP for the app and fail2ban still... focuses on incident-response and asks the reader to isolate the key signal in NGINX. Fixing forwarded headers is not enough if downstream security automation stil...NetworkIntermediate13 minProSECURITY-1319A Docker registry login succeeds and image pulls still return 401A private registry sits behind a proxy and operators can log in successfully but certain pull paths still bounce with 401 errors.SecurityIntermediate14 minProNETWORK-1324A Palo Alto decryption exception covers HTTPS and the mobile client still...A Palo Alto decryption exception covers HTTPS and the mobile client still... focuses on protocol-interoperability and asks the reader to isolate the key signal in palo-alto. Protocol preference differences between clients can make one...NetworkIntermediate14 minProNETWORK-1344A Palo Alto SSL decryption bypass fixes browsers and OCSP stapling still failsA Palo Alto SSL decryption bypass fixes browsers and OCSP stapling still fails focuses on Identity And Access and asks the reader to isolate the key signal in palo-alto. TLS validation often depends on supporting service domains beyond the pri...NetworkIntermediate14 minProNETWORK-1316A Palo Alto URL override fixes one domain and another subpath still...A Palo Alto URL override fixes one domain and another subpath still... focuses on firewall-policy-basics and asks the reader to isolate the key signal in palo-alto. URL categorization can vary within a site enough to make a single broad-loo...NetworkIntermediate14 minProSECURITY-1306A SAML logout works on the main domain and loops on the callback pathA reverse proxy serves the same app successfully until logout or ACS validation starts looping under one path.SecurityIntermediate14 minProNETWORK-1300A load balancer health check passes on TCP and still fails on HTTPA backend seems reachable at the port level and remains unhealthy behind a load balancer's application probe.NetworkIntermediate15 minProSECURITY-1276A nonce cookie exists but the app still loops on loginOne sign-in URL works and another alias for the same app loops forever despite matching provider configuration.SecurityIntermediate15 minProLINUX-1280A reverse proxy only breaks one websocket clientOne websocket-based UI or client drops repeatedly while ordinary web traffic and even other chatty websocket clients look fine.LinuxIntermediate15 minProLINUX-1289A websocket backend disconnects only for one officeA live dashboard works broadly and disconnects repeatedly only for users behind one corporate network or proxy path.LinuxIntermediate15 minProLINUX-1285Nginx serves the new certificate but OCSP stapling still failsA TLS renewal appears complete and some clients or monitors still report stapling failures after the change.LinuxIntermediate15 minProLINUX-1265A reverse proxy only breaks WebSocket auth flowsLinux incident scenario used for structured troubleshooting practice.LinuxIntermediate16 minProLINUX-1270A reverse proxy only breaks WebSocket auth flowsAn authentication layer added at the reverse proxy works for ordinary pages and suddenly breaks upgraded connections or live UI channels.LinuxIntermediate16 minProLINUX-1259A reverse proxy serves normal HTTP but WebSocket clients still failA proxy migration succeeds for normal requests while browsers or clients using WebSockets begin failing immediately.LinuxIntermediate16 minProLINUX-1277SELinux blocks a restored web tree even though file modes look correctA site migration or restore appears complete and the web server still returns permission errors on restored files.LinuxAdvanced17 minProSECURITY-1188Alternate proxy path leaves the admin surface reachable even though the canonical route is protectedSecurity scans still reach an admin path because a second proxy route exposes the same upstream without the expected controls.SecurityIntermediate18 minPro