Forum Discussion
SFTP setup for capturing client IPs
X-Forwarded-For is an HTTP header, so it has no meaning in the context of other protocols, regardless of virtual server type.
Without using the BIG-IP as the SFTP servers' default gateway, or using policy based routing to send the application servers' response traffic back to the BIG-IP, there is unfortunately no other way to have the original client IP available to the network layer once SNAT has occurred.
The logging option is a good suggestion, though I would advise using High Speed Logging (HSL) to a remote logging destination if you expect a high connection count. Have a look at the following article to get you started on HSL:
https://devcentral.f5.com/articles/-the101-irules-101-logging-amp-comments.Uh0DlmQ6Xs8
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
