<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: x-forwarded-for header parsing. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30301#M22154</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The HTTP header is "X-Forwarded-For" , as noted in the Admin and CLI guides.&amp;nbsp; If you provide me a link to the KB article in question, I can have it updated.&amp;nbsp; My guess is that someone shortened it to "x-fwd-for" because it's easier to type.&amp;nbsp; &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Mar 2013 07:17:04 GMT</pubDate>
    <dc:creator>dyang</dc:creator>
    <dc:date>2013-03-27T07:17:04Z</dc:date>
    <item>
      <title>x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30298#M22151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;With the command "set system setting ctd x-forwarded-for yes" the x-forwarded-for header is parsed to populate the source.user field in the logs.&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;However, which &lt;SPAN style="text-decoration: underline;"&gt;exact header&lt;/SPAN&gt; is actually being parsed with this command?&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Is it "x-forwarded-for"&amp;nbsp; ? ( according to the CLI guide)&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Or is it "x-fwd-for" ? (according to the KB article)&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;or both ?&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Can it be changed ?&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;How&amp;nbsp; ?&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Thanks,&lt;/P&gt;&lt;P style="color: #575757; font-family: arial,helvetica,sans-serif; font-size: 13.6px; font-style: normal; font-weight: normal; text-align: left; text-indent: 0px;"&gt;Bart&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 14:17:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30298#M22151</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2013-01-22T14:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30299#M22152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anyone ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 10:10:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30299#M22152</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2013-01-30T10:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30300#M22153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would be great if someone from PA could answer &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 07:13:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30300#M22153</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-03-27T07:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30301#M22154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The HTTP header is "X-Forwarded-For" , as noted in the Admin and CLI guides.&amp;nbsp; If you provide me a link to the KB article in question, I can have it updated.&amp;nbsp; My guess is that someone shortened it to "x-fwd-for" because it's easier to type.&amp;nbsp; &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 07:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30301#M22154</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2013-03-27T07:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30302#M22155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess its &lt;A __default_attr="1128" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, looking in the CLI guide there is both:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set deviceconfig setting ctd x-forwarded-for yes&lt;/P&gt;&lt;P&gt;set system setting ctd x-forwarded-for yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats the difference of the above (perhaps it could be described in the KB aswell)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 07:28:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30302#M22155</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-03-27T07:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30303#M22156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no difference between the two commands - they do exactly the same thing.&amp;nbsp; We most likely will not remove the duplicate command since it may cause migration issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 20:33:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30303#M22156</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2013-03-27T20:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30304#M22157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I still didn't manage to get this working in our lab infra :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@lab01(active)&amp;gt; show system setting ctd state&lt;/P&gt;&lt;P&gt;Notify user for APP block&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;/P&gt;&lt;P&gt;Alternative AHO&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;/P&gt;&lt;P&gt;Skip CTD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Parse x-forwarded-for&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Strip x-fwd-for&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;/P&gt;&lt;P&gt;Bloom Filter&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : yes&lt;/P&gt;&lt;P&gt;HTTP Proxy Use Transaction&amp;nbsp;&amp;nbsp;&amp;nbsp; : yes&lt;/P&gt;&lt;P&gt;Enable Regex Statistics&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : no&lt;/P&gt;&lt;P&gt;URL Category Query Timeout&amp;nbsp;&amp;nbsp;&amp;nbsp; : 5&lt;/P&gt;&lt;P&gt;Bypass when exceeds queue limit: yes&lt;/P&gt;&lt;P&gt;packets queued for packet capture: 5&lt;/P&gt;&lt;P&gt;whether to do packet capture after: yes&lt;/P&gt;&lt;P&gt;max. loop for packets processing: 1024&lt;/P&gt;&lt;P&gt;Not to Block HTTP Range request: yes&lt;/P&gt;&lt;P&gt;CTD ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1&lt;/P&gt;&lt;P&gt;CTD Allocator Usage&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 92%(44 MB)&lt;/P&gt;&lt;P&gt;AHO Allocator Usage&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 87%(97 MB)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet capture of a GET request:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;GET &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.microsoft.com/"&gt;http://www.microsoft.com/&lt;/A&gt;&lt;SPAN&gt; HTTP/1.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Host: www.microsoft.com&lt;/P&gt;&lt;P&gt;Pragma: no-cache&lt;/P&gt;&lt;P&gt;Cache-Control: no-cache&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;X-Forwarded-For: 10.255.224.130&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Proxy-Connection: Keep-Alive&lt;/P&gt;&lt;P&gt;X-BlueCoat-Via: 36967894f0722148&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also enabled user-id on the incoming zone.&lt;/P&gt;&lt;P&gt;That should be all to get thos working according to the DOC.&lt;/P&gt;&lt;P&gt;What else could be wrong ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 11:54:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30304#M22157</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2013-04-16T11:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30305#M22158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A __default_attr="3453" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this only works with URL filtering log.&lt;/P&gt;&lt;P&gt;Are you trying to parse in traffic log?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 13:21:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30305#M22158</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2013-04-16T13:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30306#M22159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes indeed I was looking into the traffic logs. There is no url filtering on this box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone of PA confirm that this is only working url filtering logs ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 15:00:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30306#M22159</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2013-04-16T15:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30307#M22160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks emr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found indeed the answer here : &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1528"&gt;https://live.paloaltonetworks.com/docs/DOC-1528&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 15:10:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30307#M22160</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2013-04-16T15:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header parsing.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30308#M22161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you found what you're looking for, but just in case you need further validation, the X-Forwarded-For parsing feature is only applicable to the URL filtering logs.&amp;nbsp; If you do not have a URL filtering license, you can still use the allow/block list as well as the custom categories, so you can use those to generate logs and parse the X-Forwarded-For field as indicated above.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 15:56:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-parsing/m-p/30308#M22161</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2013-04-16T15:56:25Z</dc:date>
    </item>
  </channel>
</rss>

