[Oisf-users] Suricata X-Forwarded For Question
Peter Manev
petermanev at gmail.com
Tue Oct 28 16:49:58 UTC 2014
On Tue, Oct 28, 2014 at 3:32 PM, Kevin Ross <kevross33 at googlemail.com> wrote:
> Hi,
>
> I use X-Forwarded-For overwriting. I have new proxies though and before it
> would be typically a single IP but now it is X-Forwarded-For: CLIENT_IP,
> 127.0.0.1.
>
> I have no idea why this is the case it would add that in but basically
> Suricata is taking the loopback as the overwrite address. Can I specify
> which which one to use? If not I will need to disable this which I would
> prefer not to until vendor responds :(
>
>
> Thanks,
> Kevin
>
>
I am not sure I understand - could you give an example of a log entry
or something ?
--
Regards,
Peter Manev
More information about the Oisf-users
mailing list