docs(mesh): CrowdSec CGNAT false-ban incident — mesh bypasses it
This commit is contained in:
@@ -198,3 +198,13 @@ Operator's MacBook enrolled via the GUI (Option-click → Debug → Custom Login
|
||||
node 5 `vhlk-mba26` (100.64.0.5), "Use Tailscale subnets" on. From ESH: `ping 100.64.0.3`
|
||||
and `ssh infra-ops@ana-docker.ana.internal` both work → colo subnet route + split DNS for
|
||||
`*.internal` proven from a client. (Path was still via the ESH LAN / old tunnels.)
|
||||
|
||||
### Note — the mesh is also the durable fix for CGNAT CrowdSec false-bans
|
||||
|
||||
2026-09-06: CrowdSec on ana-docker banned ESH's shared CGNAT egress (23.164.40.160,
|
||||
`custom/gitea-aggressive-crawl`) and the fortigate-mirror bouncer pushed it to the colo
|
||||
edge, blackholing Matrix/gitea/chat for the whole ESH site (see
|
||||
`~/.claude/.../memory/incident_crowdsec_cgnat_false_ban.md`). Once ESH consumes colo
|
||||
services over the mesh (100.64/10 via ana-scale) rather than the public FortiGate VIP,
|
||||
that traffic never reaches CrowdSec — a concrete win beyond replacing the tunnels, worth
|
||||
weighing when prioritising the cut-over.
|
||||
|
||||
Reference in New Issue
Block a user