Technical Tip: WAF scans against Client's Original IP in the X-Forwarded-For HTTP header
Description | This article describes how to configure X-Forwarded-For rule to identify Client's Original IP for WAF scans. |
Scope | Â FortiWeb. |
Solution | By default, FortiWeb uses the source IP address of the incoming connection when performing WAF policy enforcement, logging, and IP-based security checks such as IP Trust Lists.
![]()
FortiWeb will now perform WAF scans against the Client's Original IP as included in X-Forwarded-For. |

