Forum Discussion
Muhannad
Cirrus
Apr 21, 2026TCPDUMP in BigIP for traffic coming from distrbuited cloud.
Dears, I have an internal BigIP WAF receiving the traffic redirected by F5 Distrbuited cloud, when i doing tcpdump, i can see only the traffic sourced from distrbuited cloud IP addresses, this is...
Apr 21, 2026
Hello Muhannad​
This is expected behavior
Unfortunately, tcpdump cannot natively use the XFF header as the packet source IP, because XFF is an HTTP header (Layer 7), while tcpdump filters operate on Layer 3 / Layer 4 information.
You could either capture the traffic with tcpdump and then inspect/filter the HTTP headers in Wireshark, or use an iRule to log the information you need.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects