[Oisf-users] Suricata X-Forwarded For Question

Peter Manev petermanev at gmail.com
Tue Oct 28 16:49:58 UTC 2014


On Tue, Oct 28, 2014 at 3:32 PM, Kevin Ross <kevross33 at googlemail.com> wrote:
> Hi,
>
> I use X-Forwarded-For overwriting. I have new proxies though and before it
> would be typically a single IP but now it is X-Forwarded-For: CLIENT_IP,
> 127.0.0.1.
>
> I have no idea why this is the case it would add that in but basically
> Suricata is taking the loopback as the overwrite address. Can I specify
> which which one to use? If not I will need to disable this which I would
> prefer not to until vendor responds :(
>
>
> Thanks,
> Kevin
>
>

I am not sure I understand - could you give an example of a log entry
or something ?



-- 
Regards,
Peter Manev



More information about the Oisf-users mailing list