Skip to content
Tickwise
CriticalVelocity & proxySIG-VE-001

Modern forwarding mismatch between Velocity and the backend

Platforms
Velocity · whole network
Verified
Verified
Confidence
Confidence 90%

What it looks like in the log

Any one of these lines is enough. The agent matches them locally, on your server.

logs/latest.log
  • Your server did not send a forwarding request to the proxy
  • This server requires you to connect with Velocity.

Symptoms

  • Players cannot join the backend through Velocity: kicked right after joining
  • On the proxy: “Your server did not send a forwarding request to the proxy…” or the relayed backend kick “This server requires you to connect with Velocity.”

Cause

The player info forwarding mode on Velocity and the backend settings do not match: the proxy expects modern forwarding but the backend does not support it, or the backend expects Velocity but the proxy runs in legacy/none.

Possible causes

  • proxies.velocity.enabled is off on the backend in config/paper-global.yml, while Velocity has player-info-forwarding-mode = "modern"
  • Velocity is in legacy/none/bungeeguard mode, while the backend has Velocity support enabled (proxies.velocity.enabled: true)
  • The backend was not restarted after the forwarding settings changed
  • noteVelocity kick messages are translatable: with a non-default locale/overridden messages the proxy line will be in another language — the signature only catches the default English texts

How to fixMedium risk

  1. On Velocity, check player-info-forwarding-mode in velocity.toml — "modern" is recommended for 1.13+.
  2. On every Paper/Purpur backend, in config/paper-global.yml: proxies.velocity.enabled: true, proxies.velocity.online-mode — the same as online-mode on the proxy, proxies.velocity.secret — the contents of the proxy's forwarding.secret file (copy it locally, without sending it anywhere).
  3. In the backend's spigot.yml, set settings.bungeecord: false (legacy and modern are not used together), and in server.properties — online-mode=false.
  4. Restart the backend: the mode and secret are only read at startup.
  5. Firewall the backend port, allowing access only from the proxy's IP.

Translated from the Russian original; log lines are quoted verbatim.

Sources