Created on 06-28-2022 01:30 AM Edited on 06-06-2024 12:09 AM By Anthony_E
Description |
This article describes how to view the actual client IP details in the FortiGate logs when the FortiGate receives traffic from a proxy device connected to its LAN segment. |
Scope |
FortiGate v.6.0.0 or higher. FortiGate is handling pass-through traffic, FortiGate itself is not acting as the proxy. |
Solution |
Network layout: Users-----Proxy server----FortiGate-----Internet.
When extended logging is enabled, the following HTTP header information can be added to the raw data field in UTM logs:
Note that the UTM log will show the x-forwarded-for data only if the proxy server includes this field in the GET request.
web filter profile extended logging is used to view/log from the x-forwarded-for filed in the GET request.
The below settings need to be applied in the corresponding web filter profile:
conf webfilter profile edit <profile-name> set log-all-url enable set extended-log enable set web-extended-all-action-log enable end
Apply this web filter profile in the FLOW mode firewall policy.
config firewall policy
The above setting makes sure that all traffic (both pass-through and blocked) gets logged.
When the ‘extended-log’ option is enabled for UTM profiles, all HTTP header information for denied traffic is logged.
When enable the ‘web-extended-all-action-log’ option is enabled for the web filter profile, all HTTP header information for allowed traffic as well is logged.
Verification:
The web filter logs will now record the actual client IP as seen against the x-forwarded-for field:
date=2022-06-24 time=11:16:22 eventtime=1656054982230315333 tz="+0400" logid="0318012801" type="utm" subtype="webfilter" eventtype="ftgd_err" level="warning" vd="root" policyid=1 sessionid=51415 srcip=172.16.1.1 srcport=16717 srcintf="port10" srcintfrole="undefined" dstip=63.137.229.1 dstport=80 dstintf="port1" dstintfrole="undefined" proto=6 service="HTTP" hostname="support.fortinet.com" forwardedfor="10.1.15.1" profile="mon-all-prxy" action="passthrough" reqtype="direct" url="http://support.fortinet.com/" sentbyte=377 rcvdbyte=0 direction="outgoing" msg="A rating error occurs" error="invalid license" rawdata=" Method=GET|X-Forwarded-For= 10.1.15.1|User-Agent=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.