Forum Discussion
Bubbagump_12531
Nimbostratus
Oct 30, 2013Prevent X-Forwarded-For spoofing
We insert an X-Forwarded-For header to pass back to our web servers. One application we have looks to this header to allow or deny certain servers access to us. However, we want to prevent spoofing t...
Jeffrey_Tacy_47
Nimbostratus
Nov 05, 2013As far as I know, there's no harm in trying to remove missing headers so this rule can be pretty simple. This is a well-tested rule and should be used without any HTTP profile XFF options:
when HTTP_REQUEST {
HTTP::header remove X-Forwarded-For
HTTP::header insert X-Forwarded-For [IP::remote_addr]
}
- satish_txt_2254Mar 17, 2016
Cirrus
You nailed it... superb!!!
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
