10-05-2021 01:05 AM
Hi,
First Of all I am not sure if I am raising the question in correct category.
We have requirement from our customer. The inbound traffic coming to firewall include x forwarded for -XFF Value. Now we want to match that value in security policy. Is there any way we can achieve it? I do not see any direct options to achieve it on Palo Alto. I am running my Palo Alto on 9.1.x.
10-05-2021 01:18 AM
Hi @d.spider ,
Yes, there is a way in palo alto where it can read XFF field and use the XFF IP address in the security policy to allow/block the traffic.
This is possible in PANOS v10.
You can refer below article for the configuration steps.
NOTE- If traffic on the firewall is coming as encrypted traffic e.g.SSL request, palo alto firewall won’t be able to understand the request and so it can’t read the header unless decryption is enabled on the firewall.
If you have same case, you need to enable decryption for the specific inbound traffic which will enable palo alto to decrypt the specific traffic and read header.
Hope it helps!
10-05-2021 11:01 PM
Hi @d.spider Glad to know that it helped you. Could you please mark this question as solved by clicking Accept as Solution so it will be easy reference for others in future. Thanks!
10-05-2021 01:18 AM
Hi @d.spider ,
Yes, there is a way in palo alto where it can read XFF field and use the XFF IP address in the security policy to allow/block the traffic.
This is possible in PANOS v10.
You can refer below article for the configuration steps.
NOTE- If traffic on the firewall is coming as encrypted traffic e.g.SSL request, palo alto firewall won’t be able to understand the request and so it can’t read the header unless decryption is enabled on the firewall.
If you have same case, you need to enable decryption for the specific inbound traffic which will enable palo alto to decrypt the specific traffic and read header.
Hope it helps!
10-05-2021 01:57 AM
Thank you for your response. That’s great to know that it’s possible. I will check and update you.
10-05-2021 02:10 AM
Hi @d.spider ,
Also while asking question if you are unsure about the right category or not seeing exact category, you can ask it under Discussions 👉 General Topics section.
10-05-2021 10:38 AM
Hi Mate,
I have gone through articles shared by you and also researched few other related articles, it seems that with that given configuration my requirement should be fulfilled. Thank you for your help. Appreciate it.
10-05-2021 11:01 PM
Hi @d.spider Glad to know that it helped you. Could you please mark this question as solved by clicking Accept as Solution so it will be easy reference for others in future. Thanks!
10-06-2021 01:46 AM
I don’t know if I did that correctly. I saw few other posts and it is expected to select as solution for the post which solved the query. I guess I selected the wrong post as a solution earlier. After realisation, selected correct post as a solution. As a new joiner to the community, I am just trying to understand how it works. 🙂
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!