<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic X-forwarder header does not work when vulnerability profile action changed to block ip in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/x-forwarder-header-does-not-work-when-vulnerability-profile/m-p/540312#M1184</link>
    <description>&lt;P&gt;ISSUE REPORTED: unable to block x-forwarder ip when the action is set to block ip in the vulnerability profile&lt;BR /&gt;------------------------------------------------------------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;Discussion,observation, Troubleshooting:&lt;BR /&gt;------------------------------------------------------------------------------------------&lt;BR /&gt;++++ We have users accessing joomla website from wan and your proxy server is placed in dmz and application server is placed in lan&lt;BR /&gt;&lt;BR /&gt;++++Traffic flow:&lt;BR /&gt;&lt;BR /&gt;wan--------&amp;gt;dmz--------&amp;gt;lan&lt;BR /&gt;&lt;BR /&gt;++++ we have 3 rules RULE 1. wan to dmz (Indian cx)&lt;BR /&gt;&lt;BR /&gt;Rule 2. dmz to wan (Indian cx) url filtering profile (x forwarder enabled)+vulnerability profile(action= deny)&lt;BR /&gt;&lt;BR /&gt;RULE 3. dmz to wan (non Indian cx with exceptions) url filtering profile (x forwarder enabled)+vulnerability profile(action= deny)------------want to change action to block-ip&lt;BR /&gt;&lt;BR /&gt;In RULE 2 we would like action to be deny as we are not facing any threat attack from this traffic&lt;BR /&gt;&lt;BR /&gt;In RULE 3 we want to block certain source IP's based on vulnerability signature therefore we want to set the vulnerability profile action as (Block -IP) based on X forwarder IP(Gives actual source IP). But currently when we change action to Block-IP we are able to block Proxy Ip and not the actual source IP. IN X-forwarder column we are getting right source IP but we are not able to block it.&lt;BR /&gt;&lt;BR /&gt;When we set action as deny we are able to deny the source IP without issue but our requirement is to block the actual source IP and put it in blacklist. Right now when we use action=block ip it is blacklisting proxy ip.&lt;BR /&gt;&lt;BR /&gt;In addition I am attaching few screenshots of security policy configured and also the screenshot of traffic logs when the action is set to block ip and ip that is sent to black list.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Apr 2023 10:21:48 GMT</pubDate>
    <dc:creator>Poojadesai</dc:creator>
    <dc:date>2023-04-27T10:21:48Z</dc:date>
    <item>
      <title>X-forwarder header does not work when vulnerability profile action changed to block ip</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/x-forwarder-header-does-not-work-when-vulnerability-profile/m-p/540312#M1184</link>
      <description>&lt;P&gt;ISSUE REPORTED: unable to block x-forwarder ip when the action is set to block ip in the vulnerability profile&lt;BR /&gt;------------------------------------------------------------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;Discussion,observation, Troubleshooting:&lt;BR /&gt;------------------------------------------------------------------------------------------&lt;BR /&gt;++++ We have users accessing joomla website from wan and your proxy server is placed in dmz and application server is placed in lan&lt;BR /&gt;&lt;BR /&gt;++++Traffic flow:&lt;BR /&gt;&lt;BR /&gt;wan--------&amp;gt;dmz--------&amp;gt;lan&lt;BR /&gt;&lt;BR /&gt;++++ we have 3 rules RULE 1. wan to dmz (Indian cx)&lt;BR /&gt;&lt;BR /&gt;Rule 2. dmz to wan (Indian cx) url filtering profile (x forwarder enabled)+vulnerability profile(action= deny)&lt;BR /&gt;&lt;BR /&gt;RULE 3. dmz to wan (non Indian cx with exceptions) url filtering profile (x forwarder enabled)+vulnerability profile(action= deny)------------want to change action to block-ip&lt;BR /&gt;&lt;BR /&gt;In RULE 2 we would like action to be deny as we are not facing any threat attack from this traffic&lt;BR /&gt;&lt;BR /&gt;In RULE 3 we want to block certain source IP's based on vulnerability signature therefore we want to set the vulnerability profile action as (Block -IP) based on X forwarder IP(Gives actual source IP). But currently when we change action to Block-IP we are able to block Proxy Ip and not the actual source IP. IN X-forwarder column we are getting right source IP but we are not able to block it.&lt;BR /&gt;&lt;BR /&gt;When we set action as deny we are able to deny the source IP without issue but our requirement is to block the actual source IP and put it in blacklist. Right now when we use action=block ip it is blacklisting proxy ip.&lt;BR /&gt;&lt;BR /&gt;In addition I am attaching few screenshots of security policy configured and also the screenshot of traffic logs when the action is set to block ip and ip that is sent to black list.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 10:21:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/x-forwarder-header-does-not-work-when-vulnerability-profile/m-p/540312#M1184</guid>
      <dc:creator>Poojadesai</dc:creator>
      <dc:date>2023-04-27T10:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: X-forwarder header does not work when vulnerability profile action changed to block ip</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/x-forwarder-header-does-not-work-when-vulnerability-profile/m-p/540320#M1185</link>
      <description>&lt;P&gt;Would it be possible to assign a user-id statically to the IP address you wish to block and use that user/IP mapping in the security policy to block the user and IP?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 12:07:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/x-forwarder-header-does-not-work-when-vulnerability-profile/m-p/540320#M1185</guid>
      <dc:creator>delliott_6784</dc:creator>
      <dc:date>2023-04-27T12:07:52Z</dc:date>
    </item>
  </channel>
</rss>

