# Problem with 403 denied access when uploading multiple or big files

**URL:** <https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435>\
**Category:** Help\
**Tags:** docker, pangolin\
**Created:** [April 19, 2025, 2:17pm UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435 "2025-04-19T14:17:42Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tsunade](https://forum.hhf.technology/user_avatar/forum.hhf.technology/tsunade/32/929_2.png) [@Tsunade](https://forum.hhf.technology/u/Tsunade)\
**Post date:** [April 19, 2025, 2:17pm UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435/1 "2025-04-19T14:17:42Z")

</div>

Hi! So far im in love with Pangolin, i used a few of the guides of this forums for personalize it (like adding geoblock,etc) but seems Crowdsec is blocking me or my family members when we are uploading any type of big files or multiple files(Acess Denied Error 403), lets say on Nextcloud or our Gitea instance…

I read somewhere that i should run the command " 1. `docker inspect -f '{{range.NetworkSettings.Networks}}{{.IPAddress}}{{end}}' pangolin crowdsec`" but not sure what i should do with the output? is this:  
 ![putty_QOcvSXYJTY](https://forum-cdn.hhf.technology/original/2X/a/af601232320bba1011e1553e8138925710e0302d.png)

So if someone’s could help me it will be amazing since my family been complaining about getting access denied because of this.

---

<div class="post-metadata">

**Author:** ![hhf.technoloy](https://forum.hhf.technology/user_avatar/forum.hhf.technology/hhf.technoloy/32/68_2.png) [@hhf.technoloy](https://forum.hhf.technology/u/hhf.technoloy)\
**Post date:** [April 20, 2025, 3:05pm UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435/2 "2025-04-20T15:05:14Z")

</div>

> [@Tsunade](#):
>
> Crowdsec is blocking me or my family members when we are uploading any type of big files or multiple files(Acess Denied Error 403),

Hi there, sorry for the delayed response.

**Why CrowdSec Might Block Uploads:**

1. **Rate Limiting:** Uploading many files quickly can trigger scenarios designed to detect brute-force attacks or content scanning, exceeding requests-per-second thresholds.

2. \*_Large Request Size:_ CrowdSec block excessively large HTTP request bodies, potentially flagging large file uploads.  
try this to set in the middleware.

```auto
  middlewares:
    limit:
      buffering:
        maxRequestBodyBytes: 4000000000
        maxResponseBodyBytes: 4000000000
        memResponseBodyBytes: 2000000
        memRequestBodyBytes: 2000000

```

If the request exceeds the allowed size, it is not forwarded to the service, and the client gets a `413` and thats the reason crowdsec flags you and a block is issued.

1. **Long Request Duration:** Large uploads take time. Scenarios looking for slow attacks (like Slowloris) might mistakenly trigger if the connection stays open for a long time processing the upload.

2. **Specific Scenarios:** There might be a specific scenario (either default or one you added) that is overly sensitive to the patterns generated by your upload activity.

3. **Whitelist Trusted IPs (Simple Fix, Use Cautiously):**

4. **Create a Specific Whitelist for the Scenario/Event:**

5. **Adjust traefik middleware buffers:**

```auto
  middlewares:
    limit:
      buffering:
        maxRequestBodyBytes: 4000000000
        maxResponseBodyBytes: 4000000000
        memResponseBodyBytes: 2000000
        memRequestBodyBytes: 2000000

```

If the request exceeds the allowed size, it is not forwarded to the service, and the client gets a `413` and thats the reason crowdsec flags you and a block is issued.

there was an issue if your file is large than 2gb and it was recently closed on april 11  
[Can’t upload docker images larger than 2GB via traefik 3.0 proxy · Issue #10741 · traefik/traefik](https://github.com/traefik/traefik/issues/10741)  
[Set default ReadTimeout value to 60s by rtribotte · Pull Request #10602 · traefik/traefik](https://github.com/traefik/traefik/pull/10602)

Last and final, use middleware manager to add crowdsec on individual resources so that you get more control and keep your logs separated with log processor, you can feed crowdsec only those logs necessary.

> **[GitHub - hhftechnology/middleware-manager: A microservice that allows you to add custom...](https://github.com/hhftechnology/middleware-manager)**
>
> A microservice that allows you to add custom middleware to Pangolin resources.

> **[GitHub - hhftechnology/traefik-log-processor: Processing Traefik logs by splitting them into...](https://github.com/hhftechnology/traefik-log-processor)**
>
> Processing Traefik logs by splitting them into separate folders based on the "ServiceName" field (e.g., "5-service@http") and implementing log rotation and retention.

---

<div class="post-metadata">

**Author:** ![Tsunade](https://forum.hhf.technology/user_avatar/forum.hhf.technology/tsunade/32/929_2.png) [@Tsunade](https://forum.hhf.technology/u/Tsunade)\
**Post date:** [April 21, 2025, 8:14am UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435/3 "2025-04-21T08:14:44Z")

</div>

This fix does WORK!

By adding as you said in the dynamic config at the middlewares:

```auto
        buffering:
            buffering:
                maxRequestBodyBytes: 4000000000
                maxResponseBodyBytes: 4000000000
                memResponseBodyBytes: 2000000
                memRequestBodyBytes: 2000000

```

And then in the traefik config under middlewares before crowdsec `buffering@file`

It does the job, now me and my family members are not getting 403 errors anymore!

---

<div class="post-metadata">

**Author:** ![Tsunade](https://forum.hhf.technology/user_avatar/forum.hhf.technology/tsunade/32/929_2.png) [@Tsunade](https://forum.hhf.technology/u/Tsunade)\
**Post date:** [April 25, 2025, 5:36pm UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435/4 "2025-04-25T17:36:58Z")

</div>

@hhf.technoloy Seems is creating some troubles with Jellyfin when used on SmartTVs, i will need to incresease the bodybytes for fix it?

---

<div class="post-metadata">

**Author:** ![hhf.technoloy](https://forum.hhf.technology/user_avatar/forum.hhf.technology/hhf.technoloy/32/68_2.png) [@hhf.technoloy](https://forum.hhf.technology/u/hhf.technoloy)\
**Post date:** [April 25, 2025, 6:59pm UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435/5 "2025-04-25T18:59:45Z")

</div>

You have to balance it. What is the issue. Any logs ?

---

<div class="post-metadata">

**Author:** ![Tsunade](https://forum.hhf.technology/user_avatar/forum.hhf.technology/tsunade/32/929_2.png) [@Tsunade](https://forum.hhf.technology/u/Tsunade)\
**Post date:** [April 25, 2025, 7:05pm UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435/6 "2025-04-25T19:05:21Z")

</div>

So thats the problem, i couldnt find any logs, but when they are trying to load a movie the screen just remains black, after disabling a bit crowdsec and the buffering middleware the movie starts without any problems, i will give it a bit more testing

---

<div class="post-metadata">

**Author:** ![hhf.technoloy](https://forum.hhf.technology/user_avatar/forum.hhf.technology/hhf.technoloy/32/68_2.png) [@hhf.technoloy](https://forum.hhf.technology/u/hhf.technoloy)\
**Post date:** [April 25, 2025, 8:57pm UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435/7 "2025-04-25T20:57:33Z")

</div>

What is the media streaming at? 1080p?

---

<div class="post-metadata">

**Author:** ![Tsunade](https://forum.hhf.technology/user_avatar/forum.hhf.technology/tsunade/32/929_2.png) [@Tsunade](https://forum.hhf.technology/u/Tsunade)\
**Post date:** [April 26, 2025, 2:21pm UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435/8 "2025-04-26T14:21:25Z")

</div>

Hi! sorry for the late response, 1080p bluray yes

---

<div class="post-metadata">

**Author:** ![hhf.technoloy](https://forum.hhf.technology/user_avatar/forum.hhf.technology/hhf.technoloy/32/68_2.png) [@hhf.technoloy](https://forum.hhf.technology/u/hhf.technoloy)\
**Post date:** [April 26, 2025, 2:30pm UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435/9 "2025-04-26T14:30:57Z")

</div>

i think the issue is at the source. please check jellyfin logs

---

<div class="post-metadata">

**Author:** ![Kerry](https://forum.hhf.technology/user_avatar/forum.hhf.technology/kerry/32/3248_2.png) [@Kerry](https://forum.hhf.technology/u/Kerry)\
**Post date:** [October 5, 2025, 4:57am UTC](https://forum.hhf.technology/t/problem-with-403-denied-access-when-uploading-multiple-or-big-files/1435/10 "2025-10-05T04:57:52Z")

</div>

Crowdsec Manager

> [@CrowdSec Manager for Pangolin: User Guide](https://forum.hhf.technology/t/crowdsec-manager-for-pangolin-user-guide/579):
>
> From Bash Script to Web Application: The CrowdSec Manager Evolution Migration CrowdSec Manager has evolved from a command-line bash script into a full-featured web application. This migration represents a significant leap forward in usability, functionality, and maintainability. In this post, we’ll explore the journey, the improvements, and how to migrate from the old script-based approach to the new web-based solution. The Evolution: Why We Migrated The Original Bash Script The original Crowd…
