- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-03-2026 11:00 PM
Hello everyone,
As shown in the screenshot, you can see that the traffic has the same X-Forwarded-For (XFF) value, but one session is allowed while the other is denied.
The allowed session matched our custom application policy.
The denied session matched the any deny policy.
Based on what I am seeing, it appears that when the session is allowed, the firewall uses the original source IP, so the Country is shown as Any. However, when the session is denied, it seems to interpret the client IP using the XFF header, which is why the Country is shown as the Netherlands.
Does anyone know if this is the expected behavior? Specifically, is XFF used for source IP interpretation only when a session is denied, while the original source IP is used when it is allowed?
I searched the documentation but couldn't find any information describing this behavior. If anyone has seen this before or knows of any related documentation, I would really appreciate your insight.
Thank you in advance.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

