# IP based middleware

**URL:** <https://community.traefik.io/t/ip-based-middleware/21396>\
**Category:** Traefik v2\
**Tags:** middleware\
**Created:** [February 6, 2024, 7:13pm UTC](https://community.traefik.io/t/ip-based-middleware/21396 "2024-02-06T19:13:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rp346](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@rp346](https://community.traefik.io/u/rp346)\
**Post date:** [February 6, 2024, 7:13pm UTC](https://community.traefik.io/t/ip-based-middleware/21396/1 "2024-02-06T19:13:07Z")

</div>

Hello,

I want to set CORS restriction using middleware based on source IP for API endpoint & wondering if I can do this with Traefik V2 Middleware ?

Appreciated any kind of help here.

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [February 6, 2024, 7:27pm UTC](https://community.traefik.io/t/ip-based-middleware/21396/2 "2024-02-06T19:27:51Z")

</div>

If you want to create different middlewares per IP, then you need to create different router per IP and assign different middlewares.

---

<div class="post-metadata">

**Author:** ![rp346](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@rp346](https://community.traefik.io/u/rp346)\
**Post date:** [February 6, 2024, 9:21pm UTC](https://community.traefik.io/t/ip-based-middleware/21396/3 "2024-02-06T21:21:15Z")

</div>

Not per IP, but per subnet possible ? can you provide some example ?

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [February 6, 2024, 9:57pm UTC](https://community.traefik.io/t/ip-based-middleware/21396/4 "2024-02-06T21:57:56Z")

</div>

Create (multiple) `router` using `Host() && PathPrefix() && ClientIP()`, see [doc](https://doc.traefik.io/traefik/routing/routers/#rule). Attach a different `middleware` to each. You can use the same target `service` for each.

---

<div class="post-metadata">

**Author:** ![rp346](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@rp346](https://community.traefik.io/u/rp346)\
**Post date:** [February 7, 2024, 2:19pm UTC](https://community.traefik.io/t/ip-based-middleware/21396/5 "2024-02-07T14:19:53Z")

</div>

I am not much experience with CORS. Does following CORS Middleware looks correct ?

Allowed CORS

```auto
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
  name: cors-1
spec:
  headers:
    accessControlAllowMethods:
      - "GET"
      - "OPTIONS"
      - "PUT"
      - "POST"
      - "DELETE"
    accessControlAllowHeaders:
      - "*"
    accessControlAllowOriginList:
      - "https://*.example.org"
    accessControlMaxAge: 100
    addVaryHeader: true

```

Blocked CORS

```auto
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
  name: cors-2
spec:
  headers:
    accessControlAllowMethods: []
    accessControlAllowHeaders: []
    accessControlAllowOriginList: []

```
