Friday, September 13, 2019

Mask/Strip X-FORWARDED-FOR to the internet with ASA/Firepower

Going through an issue now where an outside vendor is filtering permission by IP, however, their application is reading the XFF field and seeing our private IP instead of the Public IP.

After doing some reserch I see that ASA/Firepower does not have the ability to strip the XFF, just wondering if anyone else has ran into this and found a solution on the source side.

So far I have told them they need to find a way to not read the field via the application



No comments:

Post a Comment