Fortinet
NSE6_FWB-6.4 · Question #57
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
The correct answer is D. Client real IP. When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.
Monitoring, Logging, and Reporting
Question
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
Options
- AFortiGate public IP
- BFortiWeb IP
- CFortiGate local IP
- DClient real IP
How the community answered
(25 responses)- A4% (1)
- B4% (1)
- D92% (23)
Explanation
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.
Topics
#X-Forwarded-For#XFF header#attack logs#client IP logging
Community Discussion
No community discussion yet for this question.