Skip to content

Bits of .NET

Daily micro-tips for C#, SQL, performance, and scalable backend engineering.

  • Asp.Net Core
  • C#
  • SQL
  • JavaScript
  • CSS
  • About
  • ErcanOPAK.com
  • No Access
  • Privacy Policy
Asp.Net Core

ASP.NET Core: Fix a Rate Limiter That Blocks Legitimate Traffic Behind a Shared Proxy IP

- 06.09.26 - ErcanOPAK

⚙️ Your Rate Limiter Is Punishing an Entire Office for One User’s Traffic

ASP.NET Core’s built-in rate limiting keys its buckets by client IP address by default – which works fine until an entire company sits behind one corporate proxy or NAT gateway, and every employee’s request counts against the SAME bucket, so one person running a busy script gets a hundred coworkers throttled alongside them.

🔎 The Problem

builder.Services.AddRateLimiter(options =>
{
    options.AddFixedWindowLimiter("api", opt =>
    {
        opt.PermitLimit = 100;
        opt.Window = TimeSpan.FromMinutes(1);
    });
});

app.MapGet("/api/data", () => Results.Ok(data))
   .RequireRateLimiting("api");

// Keyed only by IP (the default partition), every request from behind
// the same corporate NAT / proxy shares one 100-request-per-minute bucket -
// regardless of how many distinct human users are actually behind it.

✅ Fix: Partition by Something More Specific Than Raw IP

  • If users are authenticated, key the limiter by user ID or API key instead of IP – `RateLimitPartition.GetFixedWindowLimiter(key: userId, …)` – so shared infrastructure doesn’t lump distinct accounts together.
  • For anonymous traffic where IP is genuinely the only signal, consider a per-IP limit that’s generous enough to tolerate an office-sized burst, paired with a separate, stricter limit on a more specific key (session cookie, request fingerprint) to still catch actual abuse.
  • A combination of both – user/API-key partitioning for authenticated calls, coarser IP-based limiting only as a backstop – avoids collapsing ‘one bad actor’ and ‘a hundred legitimate coworkers’ into the same bucket.

⚠️ How to Confirm This Is What’s Happening

  • Log the `X-Forwarded-For` header (or whatever your proxy sets) alongside 429 responses – if many distinct forwarded IPs are converging on the same source IP hitting your rate limiter, that’s the shared-proxy signature.
  • A support ticket describing ‘random users at [company] get logged out or blocked around the same time each day’ is a strong hint that the rate limiter’s partition key is too coarse for that traffic pattern.

A rate limit keyed by IP doesn’t measure abuse – it measures how many people happen to share a network exit point, and those are rarely the same number.

— Backend Architect

Related posts:

.NET Core Logs Disappear in Production

ASP.NET Core Rate Limiting: Protect Your API from DDoS and Abuse

.NET Core: Zero-Startup Latency with Native AOT Compilation

Post Views: 2

Post navigation

C#: Why a Static Constructor Runs at a Time You Didn’t Expect
The AI Prompt That Turns Your Recurring Subscriptions List Into a Clear Case for What to Cancel

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

October 2026
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Sep    

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (973)
  • How to make theater mode the default for Youtube (952)
  • How to add default value for Entity Framework migrations for DateTime and Bool (939)
  • Get the First and Last Word from a String or Sentence in SQL (847)
  • How to select distinct rows in a datatable in C# (837)
  • How to enable, disable and check if Service Broker is enabled on a database in SQL Server (624)
  • Add Constraint to SQL Table to ensure email contains @ (590)
  • Average of all values in a column that are not zero in SQL (553)
  • How to use Map Mode for Vertical Scroll Mode in Visual Studio (526)
  • Find numbers with more than two decimal places in SQL (468)

Recent Posts

  • CSS: Fix a prefers-color-scheme Media Query That Gets Silently Overridden by a Browser Extension’s Forced Dark Mode
  • Git: Fix a Merge Commit That Silently Drops a File Because Both Branches Deleted It Differently
  • HTML5: Fix a Native Lazy-Loading Image That Never Loads Because It Sits Inside a Hidden Tab Until the User Clicks It
  • The AI Prompt That Traces a Null Reference Exception Back to the Exact Line That First Produced the Null
  • The AI Prompt That Turns a Gym Membership Contract’s Fine Print Into a Plain-English List of Cancellation Steps
  • Photoshop: Fix a Color Profile Mismatch That Makes Printed Output Look Nothing Like What You Saw On Screen
  • WordPress: Fix Search Results That Return Pages From a Theme You Deactivated Months Ago
  • Visual Studio: Fix a Test Project That Builds Fine Alone but Fails to Discover Any Tests After a NuGet Restore
  • ASP.NET Core: Fix a File Upload That Times Out on Slow Connections Only Because Kestrel’s Minimum Data Rate Feature Kicked In
  • JavaScript: Fix an Array Destructuring Default Value That Silently Never Applies Because null Was Passed Instead of Undefined

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (973)
  • How to make theater mode the default for Youtube (952)
  • How to add default value for Entity Framework migrations for DateTime and Bool (939)
  • Get the First and Last Word from a String or Sentence in SQL (847)
  • How to select distinct rows in a datatable in C# (837)

Recent Posts

  • CSS: Fix a prefers-color-scheme Media Query That Gets Silently Overridden by a Browser Extension’s Forced Dark Mode
  • Git: Fix a Merge Commit That Silently Drops a File Because Both Branches Deleted It Differently
  • HTML5: Fix a Native Lazy-Loading Image That Never Loads Because It Sits Inside a Hidden Tab Until the User Clicks It
  • The AI Prompt That Traces a Null Reference Exception Back to the Exact Line That First Produced the Null
  • The AI Prompt That Turns a Gym Membership Contract’s Fine Print Into a Plain-English List of Cancellation Steps

Social

  • ErcanOPAK.com
  • GoodReads
  • LetterBoxD
  • Linkedin
  • The Blog
  • Twitter
© 2026 Bits of .NET | Built with Xblog Plus free WordPress theme by wpthemespace.com