Review this section to know how the Sensor implements Connection Limiting policies if you have enabled XFF.
Effect on HTTP traffic when XFF is enabled
When XFF is enabled, it is assumed that all HTTP traffics on that VIDS level are XFF traffic. No connection limiting is done if the traffic is non-XFF when XFF is enabled.
Sensor checks the XFF traffic against protocol-based rules. When the connections exceed the threshold value, a response action is triggered. An alert can be raised or the connection can be blocked based on the configuration.
Note
This works irrespective of syn cookie setting. Quarantine response is not supported for XFF traffic.
Effect on HTTPS traffic when XFF is enabled
When SSL is disabled, the Sensor handles the connection limiting for HTTPS traffic based on the source IP address. It is not dependent on whether XFF is enabled or not.
When SSL is enabled, and if the Sensor cannot decrypt the traffic (no server certificate on Sensor), no connection limiting takes place for XFF and non-XFF HTTPS traffic.
When SSL is enabled, and if the Sensor can decrypt the traffic (Sensor has server certificate), no connection limiting takes place for non-XFF https traffic.
Note
The behavior of connection limiting is same for XFF HTTPS and HTTP traffics.
Effect of non-standard port on HTTP/HTTPS traffic
By default, XFF connection limiting is only performed for HTTP/HTTPS traffic on standard port. If the HTTP/HTTPS traffic runs on non-standard port, you must define the non-standard port on Manager.
Effect of XFF IP address on an alert
An XFF IP address can be IPv4 or IPv6 irrespective of the proxy IP address (it can also be IPv4 or IPv6). Connection limiting is only based on XFF IP address and not the proxy IP address.
Note
Trellix GTI does not support XFF IP address, so no Trellix GTI rule types are applied to XFF traffic.
If both XFF and connection limiting are enabled, no connection limiting processing will be done for normal non-XFF https traffic.