<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: x-forwarded-for header in traffic log on AWS VM in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342893#M85888</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;Alb takes care of HTTP traffic.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; Yes I did commit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to look in to it further, it's strange url filtering log has xff info, but&amp;nbsp; not in traffic log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 09 Aug 2020 11:26:56 GMT</pubDate>
    <dc:creator>yhlee1</dc:creator>
    <dc:date>2020-08-09T11:26:56Z</dc:date>
    <item>
      <title>x-forwarded-for header in traffic log on AWS VM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342638#M85853</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My FW is behind ALB, so I want to see original Src IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I enabled "use x-forwarded-for header in user-id" setting and user-id on the zone.&lt;/P&gt;&lt;P&gt;But there is no info on source user column in traffic log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see the information in url filtering logs using, but I want to see that in traffic log too.&lt;/P&gt;&lt;P&gt;It seems to be possible when I look into manual.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/use-xff-values-for-policies-and-logging-source-users.html#idf6817a49-c97b-4a80-9684-0c1cf3d50d56" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/use-xff-values-for-policies-and-logging-source-users.html#idf6817a49-c97b-4a80-9684-0c1cf3d50d56&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it impossible on AWS?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 06:52:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342638#M85853</guid>
      <dc:creator>yhlee1</dc:creator>
      <dc:date>2020-08-07T06:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header in traffic log on AWS VM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342675#M85857</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/103730"&gt;@yhlee1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;As long as your ALB is set to include the XFF header in the request this should work perfectly fine as long as you've followed the proper configuration steps for each option, this being on AWS doesn't do anything to effect that functionality. Sounds like a dumb question, but are you sure you ran a commit after you made the changes?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 12:58:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342675#M85857</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-08-07T12:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header in traffic log on AWS VM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342891#M85887</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/103730"&gt;@yhlee1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe another stupid question, but what type of traffic (protocol) is coming from that loadbalancer to your firewall where you expect the xff header?&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 11:22:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342891#M85887</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-09T11:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header in traffic log on AWS VM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342893#M85888</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;Alb takes care of HTTP traffic.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; Yes I did commit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to look in to it further, it's strange url filtering log has xff info, but&amp;nbsp; not in traffic log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 11:26:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342893#M85888</guid>
      <dc:creator>yhlee1</dc:creator>
      <dc:date>2020-08-09T11:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header in traffic log on AWS VM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342901#M85891</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/103730"&gt;@yhlee1&lt;/a&gt;&amp;nbsp;Are you already using PAN-OS 10? Is my assumption correct that you only see something in the xff header column but not in the source user column in url logs? If yes then this behaviour is expected. If the IP in xff header would match a username in the local user-ip-mapping table, then the username would be shown in traffic log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The question about PAN-OS 10 is because there a feature was added that would be helpful in your case:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/use-xff-values-for-ip-based-security-policy-and-logging.html#ida9a1d4bc-33e5-4ff5-9455-fe2800cb8ff0" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/use-xff-values-for-ip-based-security-policy-and-logging.html#ida9a1d4bc-33e5-4ff5-9455-fe2800cb8ff0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;(PAN-OS 10 was just released and might contain (critical) bugs. It is recommended to wait until a preferred release exist to use PAN-OS 10 in a production environment)&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 13:23:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342901#M85891</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-09T13:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: x-forwarded-for header in traffic log on AWS VM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342951#M85898</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;No, I'm not using PanOS 10 yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see XFF info in Source User field in URL logs, but not in Traffic logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If what you said is right, I completely thought wrong. I thought XFF info will show only if user-id is unknown.&lt;/P&gt;&lt;P&gt;I'll do upgrade to 10 and see what is different.&lt;/P&gt;&lt;P&gt;Thanks for the answers!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 02:09:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forwarded-for-header-in-traffic-log-on-aws-vm/m-p/342951#M85898</guid>
      <dc:creator>yhlee1</dc:creator>
      <dc:date>2020-08-10T02:09:59Z</dc:date>
    </item>
  </channel>
</rss>

