Forum Discussion
Preventing XFF header spoofing
This isa still relevant but what about when traffic comes from the AWS CDN for example? Will you want to overwrite the XFF header that the CDN configured that actually is the real ip address?
In that case better have AFM ACL or irule with data group that checks if the ip address is part of the AWS CDN known IP address range and then to not overwrite the XFF header but if it is not then to do it.
You can use an icall script to pull the AWS CDN range every day from a central server if you don't have BIG-IQ and you have many BIG-IP devices.
Knowledge sharing: Ways to trigger and schedule scripts on the F5 BIG-IP devices. | DevCentral
or use external data group
Modify large external data-groups with CLI (11.x - 16.x) (f5.com)
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com