Fortinet
FCP_FWB_AD-7.4 · Question #32
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
The correct answer is D. Client real IP. When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.
Compliance and Reporting
Question
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
Options
- AFortiGate public IP
- BFortiWeb IP
- CFortiGate local IP
- DClient real IP
How the community answered
(61 responses)- A7% (4)
- B10% (6)
- C3% (2)
- D80% (49)
Explanation
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.
Topics
#X-Forwarded-For#attack logs#client IP#XFF header
Community Discussion
No community discussion yet for this question.