Web servers are launched behind Elastic Load Balancers in AWS. In such a case, the true client IP of the web server is not displayed when alerts are generated for an attack. To view the true client IP of the web server, you have to enable the XFF header feature in the Trellix IPS Manager. For more information on the XFF header feature, see the Trellix Intrusion Prevention System Product Guide.
Configuration of Sensors to protect web servers with an Elastic Load Balancer (ELB) for Probe-based solution
- Published on Sep 11, 2026
- 1 minute(s) read
Was this article helpful?