# IP Restriction Plugin Whitelist/Blacklist Settings Bug

**URL:** <https://discuss.konghq.com/t/ip-restriction-plugin-whitelist-blacklist-settings-bug/4188>\
**Category:** General\
**Created:** [August 8, 2019, 7:34am UTC](https://discuss.konghq.com/t/ip-restriction-plugin-whitelist-blacklist-settings-bug/4188 "2019-08-08T07:34:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![robincher](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/robincher/32/1245_2.png) [@robincher](https://discuss.konghq.com/u/robincher)\
**Post date:** [August 8, 2019, 7:34am UTC](https://discuss.konghq.com/t/ip-restriction-plugin-whitelist-blacklist-settings-bug/4188/1 "2019-08-08T07:34:22Z")

</div>

Hi,

Currently have configured a service to IP restriction plugin, and the settings are as followed

For illustration purpose , let say 10.10.10.10 is my outgoing public IP address

config.blacklist

config.whitelist  
10.10.10.10/32

As such, any request that originate from 10.10.10.10 will be able to pass through Kong successfully and then proxy to the upstream service.

Interestingly, this is not the case, in fact, it blacklisted my source ip 10.10.10.10. Is it some kind of UI bug ? I changed 10.10.10.10 to config.blacklist, and the api works :).

We are using Kong-EE Docker 0.36 deployed in AWS with RDS.

Robin

---

<div class="post-metadata">

**Author:** ![tr00mb](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/tr00mb/32/660_2.png) [@tr00mb](https://discuss.konghq.com/u/tr00mb)\
**Post date:** [August 8, 2019, 11:37am UTC](https://discuss.konghq.com/t/ip-restriction-plugin-whitelist-blacklist-settings-bug/4188/2 "2019-08-08T11:37:10Z")

</div>

Hi,  
Welcome to Kong Nation.  
There are different things to consider to figure out what could be wrong in your configuration. (among them load balancer ? docker etc…)  
Looking at your test, it seems that kong does not recognise the call as issued from 10.10.10.10  
The IP restriction plugin is using ngx.var.binary\_remote\_addr and compares it with its configuration.  
There are lot of information in this post : [https://discuss.konghq.com/t/how-to-forward-clients-request-ip/384](https://discuss.konghq.com/t/how-to-forward-clients-request-ip/384)

---

<div class="post-metadata">

**Author:** ![robincher](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/robincher/32/1245_2.png) [@robincher](https://discuss.konghq.com/u/robincher)\
**Post date:** [August 9, 2019, 5:55am UTC](https://discuss.konghq.com/t/ip-restriction-plugin-whitelist-blacklist-settings-bug/4188/3 "2019-08-09T05:55:41Z")

</div>

Hi,

Maybe i didn’t articulate myself clearly.

So the scenario i observed

config.blacklist : Blank  
config.whitelist : 10.10.10.10/32

Expected Result : API should passed as the source ip is whitelisted.  
Actual Result : API failed

config.blacklist : 10.10.10.10/32  
config.whitelist : Blank

Expected Result : API should failed , as the soruce ip is set as blacklist.  
Actual Result : API Passed

---

<div class="post-metadata">

**Author:** ![tr00mb](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/tr00mb/32/660_2.png) [@tr00mb](https://discuss.konghq.com/u/tr00mb)\
**Post date:** [August 9, 2019, 9:05am UTC](https://discuss.konghq.com/t/ip-restriction-plugin-whitelist-blacklist-settings-bug/4188/4 "2019-08-09T09:05:35Z")

</div>

Hi,  
Two possibilities:  
1/ bug in the plugin (possible but I’m not aware of it)  
2/ the IP received and used by Kong is not 10.10.10.10 and then it explains your scenario

That is why I replied regarding the generic subject of client IP.
