[Ext] F5 - Source IP

Cantor, Scott cantor.2 at osu.edu
Mon Jan 23 09:30:13 EST 2017


> Make sure "x-forwarded-for" is set to true in the load balancer.  There
> maybe additional configuration settings after that.

And make sure you can't smuggle your own copy in. Citrix' NetScaler products do not protect that header and it can't be relied upon. I am given to wonder how common that is, but I urge anybody relying on that to test thoroughly or you're running vulnerable systems.

What I really suggest is not proxying at all, if you can route traffic through the device instead to preserve the source address.

-- Scott



More information about the users mailing list