cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

X-Forwarded-For (XFF) operation query

L4 Transporter

Hello,

We are evaluating the implementation of X-Forwarded-For (XFF) functionality for logs.

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/identify-users-connected-through-a...

However, this functionality was activated and affected the traffic, denying traffic that should be allowed and that contained the XFF header.

In case the feature is enabled, if the traffic contains the XFF header, - How is the traffic policy evaluated, and is the source IPv4 address no longer taken into account and replaced in the evaluation by the IPv4 address of the XFF header? - Is there any mechanism to verify the authenticity of who wrote the XFF header? 

 

Thanks so much

Who Me Too'd this topic