How to display X-Forwarded-For values in firewall logs

How to display X-Forwarded-For values in firewall logs

13461
Created On 05/11/22 02:19 AM - Last Modified 09/11/24 23:05 PM


Objective


  • To display "X-Forwarded-For" values in logs such as Traffic, Threat, Data-Filtering and URL Filtering.
  • By default, 'Use X-Forwarded-For Header' is disabled and the firewall does not read the IP addresses from X-Forwarded-For (XFF) header in client requests.
  • For displaying the XFF header in logs XFF values must first be used in the Policy. Refer Use XFF IP Address Values in Security Policy and Logging.


Environment


  • Palo Alto NGFW Firewalls
  • PAN-OS 9.1 or later
  • X-Forwarded-For (XFF) header


Procedure



For Traffic, Threat, Data Filtering, or Wildfire Submissions:
  1. Select GUI: Device > Setup > Content-ID > X-Forwarded-For Headers.
  2. Select "Enabled for Security Policy" from the "Use X-Forwarded-For Header" drop-down.
  3. Commit the changes.
  4. Navigate to GUI: Monitoring > Logs > Traffic (or Threat, Data Filtering, or Wildfire Submissions)
  5. Click the arrow to the right of any column header and select Columns and then select "X-Forwarded-For IP" to display the XFF IP in the log.

For URL Filtering logs:
  1. Select GUI: Device > Setup > Content-ID > X-Forwarded-For Headers.
  2. Select "Enabled for User-ID" from the "Use X-Forwarded-For Header" drop-down.
  3. Commit the changes.
  4. Navigate to GUI: Monitoring > Logs > URL Filtering.
  5. XFF IP will appear in the "Source User column" if it is not resolved to a username.  

Note: Use X-Forwarded-For Header for security policy and User-ID cannot be enabled at the same time.


Additional Information


Display XFF Values in Logs
Use the IP Address in the XFF Header to Troubleshoot Events

The default setting of X-Forwarded-For Header is disabled.
GUI: Device > Setup > Content-ID > X-Forwarded-For Headers > Use X-Forwarded-For Header: Disabled.
 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CpWrCAK&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language