<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The XFF IP is the same, but the country of origin appears differently; please let me know why. in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/the-xff-ip-is-the-same-but-the-country-of-origin-appears/m-p/1260872#M2471</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JiHwanHam_0-1785823048716.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72185iC13F408B66009E3F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JiHwanHam_0-1785823048716.png" alt="JiHwanHam_0-1785823048716.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;As shown in the screenshot, you can see that the traffic has the same X-Forwarded-For (XFF) value, but one session is allowed while the other is denied.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The allowed session matched our custom application policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The denied session matched the any deny policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Based on what I am seeing, it appears that when the session is allowed, the firewall uses the original source IP, so the Country is shown as Any. However, when the session is denied, it seems to interpret the client IP using the XFF header, which is why the Country is shown as the Netherlands.&lt;/P&gt;
&lt;P&gt;Does anyone know if this is the expected behavior? Specifically, is XFF used for source IP interpretation only when a session is denied, while the original source IP is used when it is allowed?&lt;/P&gt;
&lt;P&gt;I searched the documentation but couldn't find any information describing this behavior. If anyone has seen this before or knows of any related documentation, I would really appreciate your insight.&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2026 06:00:43 GMT</pubDate>
    <dc:creator>JiHwanHam</dc:creator>
    <dc:date>2026-08-04T06:00:43Z</dc:date>
    <item>
      <title>The XFF IP is the same, but the country of origin appears differently; please let me know why.</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/the-xff-ip-is-the-same-but-the-country-of-origin-appears/m-p/1260872#M2471</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JiHwanHam_0-1785823048716.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72185iC13F408B66009E3F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JiHwanHam_0-1785823048716.png" alt="JiHwanHam_0-1785823048716.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;As shown in the screenshot, you can see that the traffic has the same X-Forwarded-For (XFF) value, but one session is allowed while the other is denied.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The allowed session matched our custom application policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The denied session matched the any deny policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Based on what I am seeing, it appears that when the session is allowed, the firewall uses the original source IP, so the Country is shown as Any. However, when the session is denied, it seems to interpret the client IP using the XFF header, which is why the Country is shown as the Netherlands.&lt;/P&gt;
&lt;P&gt;Does anyone know if this is the expected behavior? Specifically, is XFF used for source IP interpretation only when a session is denied, while the original source IP is used when it is allowed?&lt;/P&gt;
&lt;P&gt;I searched the documentation but couldn't find any information describing this behavior. If anyone has seen this before or knows of any related documentation, I would really appreciate your insight.&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2026 06:00:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/the-xff-ip-is-the-same-but-the-country-of-origin-appears/m-p/1260872#M2471</guid>
      <dc:creator>JiHwanHam</dc:creator>
      <dc:date>2026-08-04T06:00:43Z</dc:date>
    </item>
  </channel>
</rss>

