- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-25-2021 11:25 PM
Hello.
I have built a simple sandwich structure test environment on GCP Cloud.
ALB
↙ ↘
FW1 FW2
↘ ↙
NLB
↙ ↘
SV1 SV2
However, in the PAN traffic log, XFF IP is only the IP of the upper ALB.
GCP's official documentation confirmed that the XFF header contains both the client IP and the LB IP.
I actually did a packet capture from the PAN, both IPs are in the XFF header.
Below is a capture of only the XFF part of the captured packet.
(By capturing the packet, both the real client IP and the ALB IP can be checked.)
Below is the XFF IP seen by the PAN.
Only the IP of the ALB that is checked in packet capture is recorded in the log.
The detailed log only checks the IP of the ALB.
The point is, if the XFF IP is simply an ALB IP in the PAN traffic log, then the XFF function doesn't seem to have any meaning.
Is there any way to see in the log the client IP and not the ALB IP?
Or am I doing something wrong?
Please help me...
Regards,
07-27-2021 08:49 PM
Hi @ttak87,
There are a couple of options around XFF in PAN-OS:
Hope this helps.
07-26-2021 05:14 AM
Hi @ttak87
You need to do settings on firewall to enable these logs. Its not enabled by default on Palo Alto.
Kindly refer below article.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIVCA0
Hope it helps!
07-26-2021 06:29 PM
Hi, @SutareMayur
Thanks for your reply.
However, I have already set the settings you taught me.
I want to check the Client IP and not the ALB IP in the log.
07-26-2021 10:35 PM
Hi @ttak87
Could you please share PA o/p of below cli command -
show system setting ctd state | match x-
07-27-2021 06:18 PM
Additionally, I looked at Palo Alto's document, and it seems that only the LB's IP is checked for the XFF IP in the proxy type LB.
If so, I think that GCP is limited in practically using XFF when using ALB.
Am I right?
07-27-2021 08:03 PM
The issue is that the firewall is using the last IP in the list and not the first. Please open a TAC case to push the fix through to engineering.
07-27-2021 08:49 PM
Hi @ttak87,
There are a couple of options around XFF in PAN-OS:
Hope this helps.
07-27-2021 10:17 PM
I understood the content.
Be able to explain well to customers.
Thanks everyone for the replies. 🙂
02-25-2023 11:03 PM
We Enabled for User-ID, still we are not receiving client real ip address.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!