docs(mesh): CrowdSec CGNAT false-ban incident — mesh bypasses it
This commit is contained in:
@@ -198,3 +198,13 @@ Operator's MacBook enrolled via the GUI (Option-click → Debug → Custom Login
|
|||||||
node 5 `vhlk-mba26` (100.64.0.5), "Use Tailscale subnets" on. From ESH: `ping 100.64.0.3`
|
node 5 `vhlk-mba26` (100.64.0.5), "Use Tailscale subnets" on. From ESH: `ping 100.64.0.3`
|
||||||
and `ssh infra-ops@ana-docker.ana.internal` both work → colo subnet route + split DNS for
|
and `ssh infra-ops@ana-docker.ana.internal` both work → colo subnet route + split DNS for
|
||||||
`*.internal` proven from a client. (Path was still via the ESH LAN / old tunnels.)
|
`*.internal` proven from a client. (Path was still via the ESH LAN / old tunnels.)
|
||||||
|
|
||||||
|
### Note — the mesh is also the durable fix for CGNAT CrowdSec false-bans
|
||||||
|
|
||||||
|
2026-09-06: CrowdSec on ana-docker banned ESH's shared CGNAT egress (23.164.40.160,
|
||||||
|
`custom/gitea-aggressive-crawl`) and the fortigate-mirror bouncer pushed it to the colo
|
||||||
|
edge, blackholing Matrix/gitea/chat for the whole ESH site (see
|
||||||
|
`~/.claude/.../memory/incident_crowdsec_cgnat_false_ban.md`). Once ESH consumes colo
|
||||||
|
services over the mesh (100.64/10 via ana-scale) rather than the public FortiGate VIP,
|
||||||
|
that traffic never reaches CrowdSec — a concrete win beyond replacing the tunnels, worth
|
||||||
|
weighing when prioritising the cut-over.
|
||||||
|
|||||||
Reference in New Issue
Block a user