# Kong rate limiting behind load balancer

**URL:** <https://discuss.konghq.com/t/kong-rate-limiting-behind-load-balancer/4840>\
**Category:** Questions\
**Created:** [November 7, 2019, 1:01pm UTC](https://discuss.konghq.com/t/kong-rate-limiting-behind-load-balancer/4840 "2019-11-07T13:01:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ryan](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ryan/32/1464_2.png) [@Ryan](https://discuss.konghq.com/u/Ryan)\
**Post date:** [November 7, 2019, 1:01pm UTC](https://discuss.konghq.com/t/kong-rate-limiting-behind-load-balancer/4840/1 "2019-11-07T13:01:23Z")

</div>

I’m using kong(1.1) containerized on a 3 node docker swarm cluster(service scaled=3), with an azure Application Gateway in front of it. With the kong rate-limiting plugin enabled, the hits are being counted as from the docker swarm internal load balancer(or the Azure App gateway), any suggestions on how I enable kong to count the real ip and not either of the load balancers

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [November 7, 2019, 8:19pm UTC](https://discuss.konghq.com/t/kong-rate-limiting-behind-load-balancer/4840/2 "2019-11-07T20:19:33Z")

</div>

You need to configure your Load-balancer to forward the real IP address in the `x-forwarded` headers or using the proxy protocol.  
Once you’ve that you need to configure Kong to read those headers. You need to set trusted\_ips setting for that:

> **[Open-Source API Management and Microservice Management](https://docs.konghq.com/1.4.x/configuration/#trusted_ips)**
>
> Secure, Manage & Extend your APIs or Microservices with plugins for authentication, logging, rate-limiting, transformations and more.
