# How to block location

**URL:** <https://community.traefik.io/t/how-to-block-location/23930>\
**Category:** Traefik v3 (latest)\
**Tags:** docker, middleware\
**Created:** [August 8, 2024, 7:40am UTC](https://community.traefik.io/t/how-to-block-location/23930 "2024-08-08T07:40:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![iali](https://avatars.discourse-cdn.com/v4/letter/i/aeb1de/32.png) [@iali](https://community.traefik.io/u/iali)\
**Post date:** [August 8, 2024, 7:40am UTC](https://community.traefik.io/t/how-to-block-location/23930/1 "2024-08-08T07:40:36Z")

</div>

Hi, I have my router configured like this:

```auto
http:
  routers:
    taiga-prod-01:
      rule: "Host(plan.company.it)"
      entryPoints:
        - web
        - websecure
      tls: true
      service: taiga-prod-01
      middlewares:
        - frame-sameorigin   

  services:
    taiga-prod-01:
      loadBalancer:
        servers:
          - url: "http://icslvpl.company.it:11003"
        passHostHeader: true
  middlewares:
    frame-sameorigin:
      headers:
        customResponseHeaders:
          X-Frame-Options: "SAMEORIGIN"

```

I wanted to make it so that when users try to move to the paths /forgot-password and /user-settings/user-change-password they get 403 or 404, since the credentials are managed by ldap and consequently I want to make these 2 pages unreachable.

I tried to look at the documentation, but I couldn't find anything.

how can i do it?

Thank you

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [August 8, 2024, 7:55am UTC](https://community.traefik.io/t/how-to-block-location/23930/2 "2024-08-08T07:55:14Z")

</div>

Add a second `router` (with different name):

```auto
rule: Host(`plan.company.it`) && ( PathPrefix(`/forgot-password `) || PathPrefix(`/user-settings/user-change-password `) )

```

Not sure if you get the desired effect by leaving `service` out completely or if you need to set a non-existing target (maybe 127.0.0.2).

---

<div class="post-metadata">

**Author:** ![iali](https://avatars.discourse-cdn.com/v4/letter/i/aeb1de/32.png) [@iali](https://community.traefik.io/u/iali)\
**Post date:** [August 8, 2024, 8:29am UTC](https://community.traefik.io/t/how-to-block-location/23930/3 "2024-08-08T08:29:29Z")

</div>

thanks @bluepuma77, does not allow management without service, I had it point to 172.0.0.2 as follows, but nothing changes I can still reach those pages.

```auto
http:
 router:
    taiga-prod-01:
      rule: "Host(`plan.company.it`)"
      entryPoints:
        - web
        - websecure
      tls: true
      service: taiga-prod-01
      middlewares:
        - frame-sameorigin   
    taiga-prod-01-block:
      rule: Host(`plan.company.it.it`) && ( PathPrefix(`/forgot-password`) || PathPrefix(`/user-settings/user-change-password`) )
      entryPoints:
        - web
        - websecure
      tls: true
      service: taiga-prod-01-block
      middlewares:
        - frame-sameorigin   
service:
    taiga-prod-01:
      loadBalancer:
        servers:
          - url: "http://icslvpl.company.it:11003"
        passHostHeader: true
    taiga-prod-01-block:
      loadBalancer:
        servers:
          - url: "http://172.0.0.2:9999"
        passHostHeader: true

```

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [August 8, 2024, 3:38pm UTC](https://community.traefik.io/t/how-to-block-location/23930/4 "2024-08-08T15:38:00Z")

</div>

At least the 2nd domain in your example is wrong.

The longer rule has higher priority, so should be matched first.

Enable and check Traefik debug log and Traefik access log in JSON format.
