nerdexam
Fortinet

NSE6_FWB-6.4 · Question #57

When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?

The correct answer is D. Client real IP. When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.

Monitoring, Logging, and Reporting

Question

When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?

Options

  • AFortiGate public IP
  • BFortiWeb IP
  • CFortiGate local IP
  • DClient real IP

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    4% (1)
  • D
    92% (23)

Explanation

When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.

Topics

#X-Forwarded-For#XFF header#attack logs#client IP logging

Community Discussion

No community discussion yet for this question.

Full NSE6_FWB-6.4 Practice