Fortinet
FCP_FWB_AD-7.4 · Question #64
A FortiWeb is deployed behind a FortiGate configured to insert the X-Forwarded-For (XFF) header in all HTTP traffic. When you view the attack logs on FortiWeb, which source IP address will you see?
The correct answer is A. Client IP. When FortiGate inserts the X-Forwarded-For (XFF) header and FortiWeb is configured to use it, the attack logs on FortiWeb will display the original client IP address from the XFF header.
Troubleshooting
Question
A FortiWeb is deployed behind a FortiGate configured to insert the X-Forwarded-For (XFF) header in all HTTP traffic. When you view the attack logs on FortiWeb, which source IP address will you see?
Options
- AClient IP
- BFortiGate local internal IP
- CFortiGate public external IP
- DFortiWeb IP
How the community answered
(33 responses)- A85% (28)
- B3% (1)
- C3% (1)
- D9% (3)
Explanation
When FortiGate inserts the X-Forwarded-For (XFF) header and FortiWeb is configured to use it, the attack logs on FortiWeb will display the original client IP address from the XFF header.
Topics
#X-Forwarded-For#attack logs#source IP#FortiGate integration
Community Discussion
No community discussion yet for this question.