For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

rnorberg's avatar
rnorberg
Icon for Nimbostratus rankNimbostratus
Nov 03, 2014

X-Forwarded-For and SNAT-clientside/serverside ssl profile

i have A vip WITH A SNAT2VIP irule, a clientside ssl profile and a serverside ssl profile, and xff enabled on the http profile.

 

the issue im seeing is that the xff header contains both the client source ip address, and the SNAT address. I am expecting to only see the client source address, but im wondering that since there is an ssl serverside profile, that is basically a proxy and is inserting the VIP into the header before it gets sent to the web server. anyone know the definitive answer on what should be seen in the xff header in this situation? thanks.

 

1 Reply

  • shaggy's avatar
    shaggy
    Icon for Nimbostratus rankNimbostratus

    is the web server also inserting XFF? I've seen instances before where the web server (apache specifically) inserts the client-IP as an xff value before it logs the connection.

     

    ssl profiles have nothing to do with inserting the xff header - that's entirely at the HTTP level (profile, irule, etc)