CrowdSec 1.8 adds bot detection to its WAF, still in alpha, which serves every visitor a page with a proof of work and a browser fingerprint. You enable it with the appsec-bot-challenge collection and its configs in the AppSec acquisition, always behind a compatible bouncer such as OpenResty 1.2.3.
CrowdSec 1.8.1 replaces fail2ban by separating detection (agent plus LAPI) from blocking (bouncers). Install the agent with the official script on Debian or Ubuntu and review the acquisition the installer generates. Then add the Traefik or firewall bouncer, the AppSec WAF with its two collections and, optionally, Cloudflare Turnstile captcha.
16 min2534.3
We use first- and third-party cookies to analyze site traffic. You can accept them, reject them, or configure your choice.
Learn more about cookies
Cookie preferences
NecessaryEssential for the site to work. Always on.
AnalyticsHelp us understand how the site is used (Google Analytics).