Helpful ReplyHot!Retrieve Client IP on web server behind Fortigate 90D, FortiOS v5.2.0,build0589

Author
vibrant
New Member
  • Total Posts : 3
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/10/20 17:38:50
  • Status: offline
2014/10/20 18:22:34 (permalink)
0

Retrieve Client IP on web server behind Fortigate 90D, FortiOS v5.2.0,build0589

Hi,
Is there a way to get the real client IP behind the Fortigate Device, by adding the add x-forwarded header? I can see it is possible using FortiWeb, but not using Fortigate in the documentation.
 
Vinodh
#1
Dave Hall
Expert Member
  • Total Posts : 1207
  • Scores: 112
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: Retrieve Client IP on web server behind Fortigate 90D, FortiOS v5.2.0,build0589 2014/10/20 19:23:32 (permalink)
0
See page 22 of the Load Balancing Handbook.
 

FCNSA /FMG-VM64/FortiAnalyzer-VM/4.0 MR3P18 5.0.9 (FWF40C/FWF80CM/FGT200B/FGT200D) / FAP220B/221C
#2
ede_pfau
Expert Member
  • Total Posts : 5220
  • Scores: 326
  • Reward points: 0
  • Joined: 2004/03/09 01:20:18
  • Location: Heidelberg, Germany
  • Status: offline
Re: Retrieve Client IP on web server behind Fortigate 90D, FortiOS v5.2.0,build0589 2014/10/21 01:48:09 (permalink)
0
This is a CLI command only option:
config firewall vip
   edit <name_str>
      set http-ip-header {enable | disable}


Ede

" Kernel panic: Aiee, killing interrupt handler!"
#3
vibrant
New Member
  • Total Posts : 3
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/10/20 17:38:50
  • Status: offline
Re: Retrieve Client IP on web server behind Fortigate 90D, FortiOS v5.2.0,build0589 2014/10/21 10:36:42 (permalink)
0
Hi,
 
Thank you guys for replying. Do I need to enable load balancing on a particular Virtual IP groupto get this option enabled? When I try to edit the Virtual IP group, I am not getting the option 'http-ip-header'.
ede_pfau
This is a CLI command only option:
config firewall vip
   edit <name_str>
      set http-ip-header {enable | disable}





 
Vinodh
#4
Dave Hall
Expert Member
  • Total Posts : 1207
  • Scores: 112
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: Retrieve Client IP on web server behind Fortigate 90D, FortiOS v5.2.0,build0589 2014/10/21 10:56:44 (permalink) ☄ Helpfulby vibrant 2014/10/21 11:35:19
0
None of the fgt devices we manage have web servers behind them, so not familiar any of those load-balancing options -- I was going to just post the same info Ede just posted, but figure I'll include the source material (on load-balancing) in case you need to do more than just enabling that one option...which btw is done via CLI to the VIP itself (not on a VIP group).  If you haven't set up anything fancy -- just port-forwarding to a single web server, you might be able to get away with disabling NAT on the firewall policy where you have the VIP set (WAN->web server).  Perhaps someone else can chime in here with a better solution.
 

FCNSA /FMG-VM64/FortiAnalyzer-VM/4.0 MR3P18 5.0.9 (FWF40C/FWF80CM/FGT200B/FGT200D) / FAP220B/221C
#5
vibrant
New Member
  • Total Posts : 3
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/10/20 17:38:50
  • Status: offline
Re: Retrieve Client IP on web server behind Fortigate 90D, FortiOS v5.2.0,build0589 2014/10/21 11:37:45 (permalink)
0
Hi Dave,
 
Yes, There is nothing fancy, and just as you had mentioned, I am just port forwarding the IP to a single webserver. I realized I had to disable NAT, but decided to see if there was a better solution. Thanks for your help!
 
Vinodh
 
Dave Hall
None of the fgt devices we manage have web servers behind them, so not familiar any of those load-balancing options -- I was going to just post the same info Ede just posted, but figure I'll include the source material (on load-balancing) in case you need to do more than just enabling that one option...which btw is done via CLI to the VIP itself (not on a VIP group).  If you haven't set up anything fancy -- just port-forwarding to a single web server, you might be able to get away with disabling NAT on the firewall policy where you have the VIP set (WAN->web server).  Perhaps someone else can chime in here with a better solution.
 




#6
Marcin
New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2017/08/16 07:04:40
  • Status: offline
Re: Retrieve Client IP on web server behind Fortigate 90D, FortiOS v5.2.0,build0589 2017/08/18 03:11:48 (permalink)
0
I would like to ask a similar thing as in the subject.
I have a linux server on the network and would like to be able to see from what
public addresses were trying to log in to SSH on port 22. All these addresses are
present in the address of the router and I am interested in seeing the real a
adresses how can this be done?

post edited by Marcin - 2017/08/18 03:12:54
#7
Jump to:
© 2017 APG vNext Commercial Version 5.5