<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XXF and building Security Policy in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/xxf-and-building-security-policy/m-p/576728#M2611</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203913"&gt;@sxk654&lt;/a&gt;&amp;nbsp;- please refer to &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/use-xff-values-for-ip-based-security-policy-and-logging" target="_self"&gt;this&lt;/A&gt; document within the user manual; it describes how to collect XFF details and how to use this information in logging.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Feb 2024 00:47:27 GMT</pubDate>
    <dc:creator>iarobertson</dc:creator>
    <dc:date>2024-02-09T00:47:27Z</dc:date>
    <item>
      <title>XXF and building Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/xxf-and-building-security-policy/m-p/576437#M2599</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to know how I would go about creating security policies based of the XFF headers please, any help would be appreciated.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have read the documentation and I have to enable the XFF header&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI class="li substep"&gt;Select&lt;SPAN&gt;&amp;nbsp;-&amp;gt;&lt;/SPAN&gt;Device -&amp;gt;Setup -&amp;gt;Content-ID and edit the X-Forwarded-For Headers settings.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I need some help after that, so from my understanding this will populate the XFF header, can this be used within the security policy directly?&amp;nbsp; I dont see any option to use XXF as the source IP address under the security policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm a little unsure of how to use the XFF header to build out a security policy to allow / deny traffic from the true customer source IP address rather than the proxy server address which is sit in between&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/security-policy/administration/identify-users-connected-through-a-proxy-server/add-xff-values-to-url-filtering-logs" target="_blank"&gt;https://docs.paloaltonetworks.com/network-security/security-policy/administration/identify-users-connected-through-a-proxy-server/add-xff-values-to-url-filtering-logs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 12:10:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/xxf-and-building-security-policy/m-p/576437#M2599</guid>
      <dc:creator>sxk654</dc:creator>
      <dc:date>2024-02-07T12:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: XXF and building Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/xxf-and-building-security-policy/m-p/576521#M2602</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203913"&gt;@sxk654&lt;/a&gt;&amp;nbsp;- if I understand correctly, you want to use the X-Forwarded-For header, populated by another device, in your ruleset.&amp;nbsp; Is that correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In that case you probably don't want to populate the XFF header, because doing so will add the NGFW's IP address to the XFF header.&amp;nbsp; That is more useful for subsequent downstream devices.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If my assessment of your need is correct, and assuming that your proxy "correctly" fills X-Forwarded-For and you're running PAN-OS 10.x or above, the steps required are as follows.&amp;nbsp; Please note that X-Forwarded-For will only be visible for a subset of your traffic, specifically HTTP and (if you have appropriate decryption policies) HTTPS traffic.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to Objects -&amp;gt; Security Profiles -&amp;gt; URL Filtering and enable, configure, or add an appropriate URL Filtering profile.&lt;/LI&gt;
&lt;LI&gt;Select URL Filtering Settings and enable X-Forwarded-For.&lt;/LI&gt;
&lt;LI&gt;Click OK.&lt;/LI&gt;
&lt;LI&gt;Attach the relevant policy edited in the first 3 steps to a security policy rule: select the rule in Policies -&amp;gt; Security.&lt;/LI&gt;
&lt;LI&gt;Select Actions, set Profiles in Profile Type, and select the URL Filtering profile described above.&lt;/LI&gt;
&lt;LI&gt;Click OK, then commit your configuration.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 07 Feb 2024 21:43:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/xxf-and-building-security-policy/m-p/576521#M2602</guid>
      <dc:creator>iarobertson</dc:creator>
      <dc:date>2024-02-07T21:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: XXF and building Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/xxf-and-building-security-policy/m-p/576614#M2605</link>
      <description>&lt;P&gt;Hi &amp;amp; thanks for the detailed reply&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Correct, the design at the moment is customer src IP -&amp;gt; Proxy -&amp;gt; Palo&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;amp; yes, I'm not interested in passing the Palo IP into the headers for the downstream device but want to build out a security policy to allow traffic from the true customer IP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the moment, while looking at the logs, I dont see any actual customer IPs, all source IP belong to the proxy IP addresses subnet, as expected.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what you are saying, I will need to enable&amp;nbsp;&lt;SPAN&gt;URL Filtering Settings and enable X-Forwarded-For and then assign this to the security policy.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Then edit the security policy and add in the customer's true source IP subnet / IP to the source addess section of the secuirty rule?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Enabling the&amp;nbsp;URL X-Forwarded-For, will then this populate the Monitor tab field with ' X-Fordwarded-For IP ' ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So that I can see what the true IP is? Also, do you know how to filter the traffic logs to show traffic from a certain customer ? similar to&amp;nbsp;( addr.src in '1.1.1.1' ) I can't seem to work out the filter for it, something like&amp;nbsp;( x-forwarded in '2.2.2.2' )&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 13:30:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/xxf-and-building-security-policy/m-p/576614#M2605</guid>
      <dc:creator>sxk654</dc:creator>
      <dc:date>2024-02-08T13:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: XXF and building Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/xxf-and-building-security-policy/m-p/576728#M2611</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203913"&gt;@sxk654&lt;/a&gt;&amp;nbsp;- please refer to &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/use-xff-values-for-ip-based-security-policy-and-logging" target="_self"&gt;this&lt;/A&gt; document within the user manual; it describes how to collect XFF details and how to use this information in logging.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 00:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/xxf-and-building-security-policy/m-p/576728#M2611</guid>
      <dc:creator>iarobertson</dc:creator>
      <dc:date>2024-02-09T00:47:27Z</dc:date>
    </item>
  </channel>
</rss>

