[haproxy] enabled = true bantime = 600 findtime = 10 maxretry = 100 filter = haproxy-basic backend = systemd journalmatch = _COMM=haproxy port = http,https,8448 ignoreip = {{ wireguard.cidr }},{{ nebula.cidr }},{{ pve_hosts.internal_cidr }} [traefik] enabled = true filter = haproxy-basic # Not actually used port = http,https,8448 ignoreip = {{ wireguard.cidr }},{{ nebula.cidr }},{{ pve_hosts.internal_cidr }}