X-Forwarded-For HTTP Header implementation - explanation needed

Viewed 810

I was assign a task by my direct manager to make sure that all the websites in the company will have "X-Forwarded-For" HTTP Header set, in order to receive the original IP of the users for our Web Application Firewall logs.

I am not a developers, but I need to make sure our developers do that, and they seem to not understand what needs to be in the value of the header.

Because looking at some examples, it seemed that some people put specific IP like this:

X-Forwarded-For: <client>, <proxy1>, <proxy2>

which doesn't make any sense to me, because how can u type the IP in the value when it is completely random for each one?

Basically, I need that our logs will contain the real IP from each computer which surf behind a proxy or a load balancer.

Would like for some help : )

Thanks!

1 Answers

If you have one reverse proxy (or load balancer) between the client and the application server, then the proxy should add the header:

X-Forwarded-For: <client>

before forwarding the request on to the application server. The application server receives the request from the proxy IP but can deduce the client's IP from the value of the header.


If you have two reverse proxies (or load balancers) between the client and the application server, the first proxy (the one nearest the client) acts the same as above.

The second proxy receives the request from proxy1's IP and also receives the X-Forwarded-For header from proxy1. It then appends the IP address from where the request was receives (proxy1) and passes the updated header to the application server as:

X-Forwarded-For: <client>, <proxy1>

Each proxy or load balancer is responsible for creating the header if it does not already exist, and appending the IP address of the from where the request was received (i.e. the previous step in the chain).

Only the first IP address is necessary to identify the client, the remaining IP addresses are necessary to ensure that the header has not been faked.

Related