Hacker News new | ask | show | jobs
by bivlked 87 days ago
ran into this with UFW + Cloudflare on a VPS. had a rule in UFW that should have been denying a range, but Cloudflare was proxying the request so UFW saw Cloudflare's IP instead of the client's. took me way too long to figure out.

the "first match wins" vs "most specific wins" difference between systems is brutal when you're debugging at 2am.