Get the App
SLTechnology News&Howtos  ›  Network Security  › 

X-Forwarded-For insertion and rewriting-F5 irules and NetScaler Appexpert

Shulou Source: shulou.com Published: 2022-06-01 05:36:02 10月04日 Update

Requirements: when the HTTP request contains the header of X-Forwarded-For, this value is replaced by the policy with a separate client IP address. If there is no X-Forwarded header, the header is added and the client IP address value is added.

F5 iRules:

When HTTP_REQUEST {

If {[HTTP::header exists X-Forwarded-For]} {

HTTP::header replace X-Forwarded-For "[HTTP::header X-Forwarded-For], [IP::]

Client_addr] "

} else {

HTTP::header insert X-Forwarded-For [IP::client_addr]

}

}

NetScaler:

Add rewrite action xforward replace HTTP.REQ.HEADER ("X-Forwarded-For") CLIENT.IP.SRC

Add rewrite policy xforward_check_pol "HTTP.REQ.HEADER (\" X-FORWARDEDFOR\ ") .EXISTS"

Add rewrite action xforward_add insert_http_header X-FORWARDED-FOR CLIENT.IP.SRC

Add rewrite policy xforward_add_pol "HTTP.REQ.HEADER (\" X-FORWARDEDFOR\ ") .EXISTS.NOT"

Xforward_add

Bind globally or at the vServer level

Tags: Address customer client global policy level requirements subcontract Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology OPPO Reno Shulou Information Shulou Tech Info Redmi