CrowdSec remediation blocks legitimate traffic after upgrade to 26.7.1

Started by kohly, July 21, 2026, 08:42:53 PM

Previous topic - Next topic
Hi,

after upgrading both of our HA firewalls to OPNsense 26.7.1 we observed an issue with the CrowdSec remediation component.

When Enable Remediation Component (IPS) is enabled, a large amount of legitimate traffic is blocked by the automatically created CrowdSec (IPv4) firewall rules. This affects both inbound and outbound connections. Among others, we observed failures with WireGuard, Wazuh agents, MeshCentral agents and normal HTTPS traffic.

The firewall log contains entries such as:

  • CrowdSec (IPv4) in
  • CrowdSec (IPv4) out

Disabling only Enable Remediation Component (IPS) immediately restores normal operation. The CrowdSec agent, log processor (IDS) and LAPI can remain enabled without any issues.

We also tested allowlisting the firewall's own WAN/CARP addresses, but this did not change the behaviour.

At the moment the only usable workaround is to leave the remediation component disabled.

If there is any additional information or debugging output that would be helpful, I would be happy to provide it.

Best regards
kohly