<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XFF in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/xff/m-p/562249#M1968</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I am hosting a website behind ngfw.&lt;/P&gt;
&lt;P&gt;The traffic comes from google load balancer, and i would like to LOG ONLY the x-forward IP (the original).&lt;/P&gt;
&lt;P&gt;I have used this kb:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/add-xff-values-to-url-filtering-logs" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/add-xff-values-to-url-filtering-logs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But my URL filtering logs are empty.&lt;/P&gt;
&lt;P&gt;Maybe it has to do with its inbound? i mean, the URL filtering works also for inbound traffic? (i.e protect a web site)&lt;/P&gt;</description>
    <pubDate>Wed, 18 Oct 2023 11:40:39 GMT</pubDate>
    <dc:creator>chens</dc:creator>
    <dc:date>2023-10-18T11:40:39Z</dc:date>
    <item>
      <title>XFF</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/xff/m-p/562249#M1968</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I am hosting a website behind ngfw.&lt;/P&gt;
&lt;P&gt;The traffic comes from google load balancer, and i would like to LOG ONLY the x-forward IP (the original).&lt;/P&gt;
&lt;P&gt;I have used this kb:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/add-xff-values-to-url-filtering-logs" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/add-xff-values-to-url-filtering-logs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But my URL filtering logs are empty.&lt;/P&gt;
&lt;P&gt;Maybe it has to do with its inbound? i mean, the URL filtering works also for inbound traffic? (i.e protect a web site)&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 11:40:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/xff/m-p/562249#M1968</guid>
      <dc:creator>chens</dc:creator>
      <dc:date>2023-10-18T11:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: XFF</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/xff/m-p/563130#M2003</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/80392"&gt;@chens&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I know, we need to enable the parsing of XFF value in http traffic. Did you enabled it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It can be enable using below command -&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="ckeditor_codeblock"&gt;&lt;SPAN&gt;set system setting ctd x-forwarded-for yes|no&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 15:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/xff/m-p/563130#M2003</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2023-10-25T15:35:07Z</dc:date>
    </item>
  </channel>
</rss>

