nerdexam
Fortinet

FCP_FWB_AD-7.4 · Question #32

When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?

The correct answer is D. Client real IP. When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.

Compliance and Reporting

Question

When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?

Options

  • AFortiGate public IP
  • BFortiWeb IP
  • CFortiGate local IP
  • DClient real IP

How the community answered

(61 responses)
  • A
    7% (4)
  • B
    10% (6)
  • C
    3% (2)
  • D
    80% (49)

Explanation

When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.

Topics

#X-Forwarded-For#attack logs#client IP#XFF header

Community Discussion

No community discussion yet for this question.

Full FCP_FWB_AD-7.4 Practice