# How to configure rate-limiting on consumer

**URL:** <https://discuss.konghq.com/t/how-to-configure-rate-limiting-on-consumer/9214>\
**Category:** Questions\
**Created:** [October 19, 2021, 1:37pm UTC](https://discuss.konghq.com/t/how-to-configure-rate-limiting-on-consumer/9214 "2021-10-19T13:37:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bel81](https://avatars.discourse-cdn.com/v4/letter/b/ecb155/32.png) [@bel81](https://discuss.konghq.com/u/bel81)\
**Post date:** [October 19, 2021, 1:37pm UTC](https://discuss.konghq.com/t/how-to-configure-rate-limiting-on-consumer/9214/1 "2021-10-19T13:37:24Z")

</div>

Hello,

I have created a consumer with username=XXX and custom.id=XXX and attached to him the rate-limit plug-in.  
Then I have set the global LDAP authentication plugin name=“ldap-auth”. The ldap-auth plug-in works well having  
“Authentication base64(username:password)” headers. But it seems that the “username=XXX” is not matched with the consumer XXX as rate-limits are not applied.

I have created the rate-limit plug-in with the following request:

curl -X POST [http://localhost:8001/consumers/XXX/plugins](http://localhost:8001/consumers/XXX/plugins)  
–data “name=rate-limiting”  
–data “config.minute=2”  
–data “config.policy=cluster”

When I send 3 requests on behalf of the user XXX, it does not prevent me from sending more requests.  
On the other hand, when I set the rate-limit plug-in on route, it works.

How is the mapping of the API request to the consumer entity done?  
I use docker image of the latest Kong version (2.6.0)

Update on troubleshooting:

I’ve used “key-auth” to match API request with the consumer. So i assume it is matched with the defined consumer, however no information headers are returned back to client, such as:

RateLimit-Limit: 6  
RateLimit-Remaining: 4  
RateLimit-Reset:

On the other hand, when I set rate-limiting plug-in on a route then I get these headers back and it works.

Update: I have cleared by Postgres DB of Kong and completely redone the following basic scenario

> <https://github.com/Kong/kong/issues/7168#issuecomment-846071983>
>
> \### Summary
> 
> I have two rate limiting plugins set up on a route: one for all c…onsumers, and one for a specific consumer id.
> I would expect the more specific plugin to apply when calling the route (per #6553) but no matter what i try, only the rate limiting apply to all consumers apply.
> 
> \### Steps To Reproduce
> 
> 1. Route Set Up
> \`\`\`
> {
> "id": "b3b\[...\]",
> "path\_handling": "v0",
> "paths": \[
> "\\/v1\\/my-route"
> \],
> "destinations": null,
> "headers": {},
> "protocols": \[
> "http",
> "https"
> \],
> "created\_at": 1610120374,
> "snis": \[\],
> "service": {
> "id": "136\[...\]"
> },
> "name": "my-route",
> "strip\_path": false,
> "preserve\_host": false,
> "regex\_priority": 0,
> "updated\_at": 1611150996,
> "sources": null,
> "methods": \[\],
> "https\_redirect\_status\_code": 426,
> "hosts": \[\*redacted\*\],
> "tags": \[\]
> }
> \`\`\`
> 2. Rate Limiting Plugin for all consumer on my-route
> \`\`\`
> {
> "created\_at": 1616501241,
> "id": "805\[...\]",
> "tags": \[\],
> "enabled": true,
> "protocols": \[
> "grpc",
> "grpcs",
> "http",
> "https"
> \],
> "name": "rate-limiting",
> "consumer": null,
> "service": null,
> "route": {
> "id": "b3b\[...\]"
> },
> "config": {
> "hide\_client\_headers": false,
> "minute": 20,
> "policy": "cluster",
> "month": null,
> "redis\_timeout": 2000,
> "limit\_by": "consumer",
> "redis\_password": null,
> "second": null,
> "day": null,
> "redis\_database": 0,
> "year": null,
> "hour": null,
> "redis\_host": null,
> "redis\_port": 6379,
> "header\_name": null,
> "fault\_tolerant": true
> }
> }
> \`\`\`
> 3. Rate Limiting Plugin for my-route for consumer 4c7
> \`\`\`
> {
> "created\_at": 1621347893,
> "id": "59a\[...\]",
> "tags": null,
> "enabled": true,
> "protocols": \[
> "grpc",
> "grpcs",
> "http",
> "https"
> \],
> "name": "rate-limiting",
> "consumer": {
> "id": "4c7\[...\]"
> },
> "service": null,
> "route": {
> "id": "b3b\[...\]"
> },
> "config": {
> "hide\_client\_headers": false,
> "minute": 10,
> "policy": "cluster",
> "month": null,
> "redis\_timeout": 2000,
> "limit\_by": "consumer",
> "redis\_password": null,
> "second": null,
> "day": null,
> "redis\_database": 0,
> "year": null,
> "hour": null,
> "redis\_host": null,
> "redis\_port": 6379,
> "header\_name": null,
> "fault\_tolerant": true
> }
> }
> \`\`\`
> 
> When calling "my-route" with the API keys associated with the 4c7 consumer, I would expect my rate to get limited after 10 calls per minute, as defined above. Instead, I hit the rate limit after 20 request per minute, which is the limit for all consumers. When I disable the rate limit for all consumers, I do not get rate limited at all.
> 
> What is the issue? How can I fix the configuration to reflect the rate limiting desired?
> Thanks in advance for the help!
> 
> \### Additional Details & Logs
> 
> \- Kong version 2.1.0
> I can provide more details if it becomes relevant

The result is the same. Only route rate-limiting plugin is applied.

Thanks for any hint or suggestions how to better troubleshoot it.

---

<div class="post-metadata">

**Author:** ![bel81](https://avatars.discourse-cdn.com/v4/letter/b/ecb155/32.png) [@bel81](https://discuss.konghq.com/u/bel81)\
**Post date:** [October 20, 2021, 2:34pm UTC](https://discuss.konghq.com/t/how-to-configure-rate-limiting-on-consumer/9214/2 "2021-10-20T14:34:49Z")

</div>

Actually, the referenced example above with httpbin API worked for me in the end.  
So then I mounted into it my application and it worked as well.  
But then I added the “ldap-auth” plug-in and I got to the problem that I described here.

Isn’t it a bug? I didn’t read anywhere that it cannot be used together.

---

<div class="post-metadata">

**Author:** ![fomm](https://avatars.discourse-cdn.com/v4/letter/f/ea666f/32.png) [@fomm](https://discuss.konghq.com/u/fomm)\
**Post date:** [October 20, 2021, 11:25pm UTC](https://discuss.konghq.com/t/how-to-configure-rate-limiting-on-consumer/9214/3 "2021-10-20T23:25:02Z")

</div>

Hi bel81,

from what you describe, it seems that you have

LDAP auth → Global  
Keyauth → on Route  
rate limiting → Consumer

Did you use keyauth and LDAP at the same time? So when you authenticate, you need to pass in apiKey and Authorization basic header. Is that right?

---

<div class="post-metadata">

**Author:** ![bel81](https://avatars.discourse-cdn.com/v4/letter/b/ecb155/32.png) [@bel81](https://discuss.konghq.com/u/bel81)\
**Post date:** [October 21, 2021, 6:25am UTC](https://discuss.konghq.com/t/how-to-configure-rate-limiting-on-consumer/9214/4 "2021-10-21T06:25:24Z")

</div>

Hi fomm,

yes, i was using LDAP auth with Key auth and rate limiting at the same time.  
I’ve tried LDAP auth globally and also on a route only.

I am actually using Authorization LDAP base64(username:password) header.  
I’ve tried also to configure Key auth’s key as “Authorization” storing the “LDAP base64(username:password)” on the consumers/USERID/key-auth directly but having LDAP auth plug-in anywhere causes that the rate-limiting is not properly evaluated for the consumer.

---

<div class="post-metadata">

**Author:** ![fomm](https://avatars.discourse-cdn.com/v4/letter/f/ea666f/32.png) [@fomm](https://discuss.konghq.com/u/fomm)\
**Post date:** [October 21, 2021, 10:29am UTC](https://discuss.konghq.com/t/how-to-configure-rate-limiting-on-consumer/9214/5 "2021-10-21T10:29:57Z")

</div>

I think that is because LDAP auth plugin does NOT have consumer mapping.

When you are using multiple authentication plugins in `AND` method, the last plugin executed sets the credential.

> **[Authentication Reference - v2.6.x | Kong Docs](https://docs.konghq.com/gateway-oss/2.6.x/auth/#multiple-authentication)**
>
> Documentation for Kong, the Cloud Connectivity Company for APIs and Microservices.

Because LDAP auth plugin has a lower priority(1002) than key auth (1003), LDAP auth plugin will be used for consumer mapping but it does not have this function.

You can verify that by using basic auth and LDAP auth plugin. See if you can get the header.

#################################################

I just tested it and basic auth + LDAP auth works as I expected.

---

<div class="post-metadata">

**Author:** ![bel81](https://avatars.discourse-cdn.com/v4/letter/b/ecb155/32.png) [@bel81](https://discuss.konghq.com/u/bel81)\
**Post date:** [October 21, 2021, 1:03pm UTC](https://discuss.konghq.com/t/how-to-configure-rate-limiting-on-consumer/9214/6 "2021-10-21T13:03:44Z")

</div>

Thanks for you time and the answer.

What I see as a problem is that I will have to provision users’ credentials in to Kong DB in order to be able to use rate-limits per client/consumer. Then the LDAP plugin is useless. One authentication is enough.
