<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XFF IP address not seen in traffic logs in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/xff-ip-address-not-seen-in-traffic-logs/m-p/590104#M2190</link>
    <description>&lt;P&gt;It turns out this works but only displays the XFF IP in denied traffic, not allowed.&lt;/P&gt;
&lt;P&gt;There is also a fix in 11.1.3 for this, so this should start showing the XFF IP in allowed traffic also. Bug ID PAN-233463.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2024 18:31:42 GMT</pubDate>
    <dc:creator>Keith_S</dc:creator>
    <dc:date>2024-06-21T18:31:42Z</dc:date>
    <item>
      <title>XFF IP address not seen in traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/xff-ip-address-not-seen-in-traffic-logs/m-p/589935#M2189</link>
      <description>&lt;P&gt;I am trying to get the PA firewall to display and use the the x-forwarded-for (XFF) header in incoming web browsing traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I must be missing something.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have an Azure application gateway which is inserting the client_ip in the header, and stripping the port, as instructed:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/security-policy/administration/identify-users-connected-through-a-proxy-server/use-xff-values-for-ip-based-security-policy-and-logging" target="_blank"&gt;Use XFF IP Address Values in Security Policy and Logging (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIVCA0" target="_blank"&gt;How to Enable Support for the X-Forwarded-For HTTP Header - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://azure.microsoft.com/en-us/blog/rewrite-http-headers-with-azure-application-gateway/" target="_blank"&gt;Rewrite HTTP headers with Azure Application Gateway | Microsoft Azure Blog&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Behind the Azure AG is a VM300 (4x vCPU firewall) which should be showing the XFF client IP in the traffic logs.&lt;/P&gt;
&lt;P&gt;I enabled the XFF for client IP, tried both thru the WebUI and at the CLI.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Keith_S_0-1718832288886.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60425i5FE4765F7A7C383E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Keith_S_0-1718832288886.png" alt="Keith_S_0-1718832288886.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I have SSL decryption working and I'm testing on ports 80 and 443 anyway.&lt;/P&gt;
&lt;P&gt;I have the XFF column in the log displayed, but it's never populated.&lt;/P&gt;
&lt;P&gt;I have a URL filtering license and checked the XFF box on the url profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The status is that the XFF IP is shown on some entries in the URL logs.&lt;/P&gt;
&lt;P&gt;The XFF IP is never shown in the traffic logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some questions:&lt;/P&gt;
&lt;P&gt;I examined packet captures with Wireshark and found that the XFF IP is in some packets, but not in every incoming packet. Is that normal?&lt;/P&gt;
&lt;P&gt;What am I missing?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2024 21:32:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/xff-ip-address-not-seen-in-traffic-logs/m-p/589935#M2189</guid>
      <dc:creator>Keith_S</dc:creator>
      <dc:date>2024-06-19T21:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: XFF IP address not seen in traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/xff-ip-address-not-seen-in-traffic-logs/m-p/590104#M2190</link>
      <description>&lt;P&gt;It turns out this works but only displays the XFF IP in denied traffic, not allowed.&lt;/P&gt;
&lt;P&gt;There is also a fix in 11.1.3 for this, so this should start showing the XFF IP in allowed traffic also. Bug ID PAN-233463.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 18:31:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/xff-ip-address-not-seen-in-traffic-logs/m-p/590104#M2190</guid>
      <dc:creator>Keith_S</dc:creator>
      <dc:date>2024-06-21T18:31:42Z</dc:date>
    </item>
  </channel>
</rss>

