X-Forwarded-For insertion and rewriting-F5 irules and NetScaler Appexpert
Requirements: when the HTTP request contains the header of X-Forwarded-For, this value is replaced by the policy with a separate client IP address. If there is no X-Forwarded header, the header is added and the client IP address value is added.
F5 iRules:
When HTTP_REQUEST {
If {[HTTP::header exists X-Forwarded-For]} {
HTTP::header replace X-Forwarded-For "[HTTP::header X-Forwarded-For], [IP::]
Client_addr] "
} else {
HTTP::header insert X-Forwarded-For [IP::client_addr]
}
}
NetScaler:
Add rewrite action xforward replace HTTP.REQ.HEADER ("X-Forwarded-For") CLIENT.IP.SRC
Add rewrite policy xforward_check_pol "HTTP.REQ.HEADER (\" X-FORWARDEDFOR\ ") .EXISTS"
Add rewrite action xforward_add insert_http_header X-FORWARDED-FOR CLIENT.IP.SRC
Add rewrite policy xforward_add_pol "HTTP.REQ.HEADER (\" X-FORWARDEDFOR\ ") .EXISTS.NOT"
Xforward_add
Bind globally or at the vServer level