A client connection to a web server might be established through an HTTP proxy or load balancer. When an explicit (non-transparent) proxy server (or load-balancer farm) is used, it closes the original client connection and creates a secondary connection between itself and the intended destination IP address. If the Sensor monitoring ports sit on the proxied side of the connection, all alerts will show the external IP address of the proxy server as either the source or destination IP address (depending on the direction of the attack) instead of the original source IP address. Therefore, the actual IP address is not available in alerts.
If you enable X-Forwarded-For (XFF) header parsing in the Sensor, the Sensor can parse the XFF field in the HTTP header to identify the original source IP address. In addition, the Sensor can parse True-Client-IP in the HTTP header (for example, Akamai) to obtain the original source IP address.
If your proxy server or the load balancer supports XFF header, the Sensor can parse the XFF header for HTTP connections, by which it recognizes the proxy servers or load balancers the data packet has traversed through. The alerts generated while the Sensor is positioned on the proxied side of the connection, include both the external proxy IP address and the original endpoint IP address.
When attacks are detected, the Sensor forwards both proxy IP address and original source IP address to the alerting mechanism and indicates them in the alert messages sent to the Manager.
The XFF feature supports enabling/disabling per interface or subinterface. It supports both IPv4 and IPv6 addresses.
Enabling XFF header parsing for a Sensor gives you the ability to use original source IP addresses in your firewall policies and quarantine.
In case of firewall policies, when executing ACL Drop, Deny, Scan, or Ignore, the Sensor uses the original source IP address.
Note
Depending on the traffic order, some firewall policies will not work as expected for the original source IP address as the Sensor detects the traffic before parsing the XFF header.
Note
If you have configured any ACL rules such as Drop or Deny for the source or destination IP address, which is the proxy IP address, these rules will be run first. This is because the Sensor acts on these rules before parsing the XFF header or HTTP header.
In case of quarantine, any quarantine resulting from an attack will quarantine the original source IP address and not the proxy IP address.
Note
The Ignore rules feature is unsupported with X-Forwarded-For (XFF) header parsing feature for HTTP or HTTPS traffic.