Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
vibrant
New Contributor II

Retrieve Client IP on web server behind Fortigate 90D, FortiOS v5.2.0,build0589

Hi,

Is there a way to get the real client IP behind the Fortigate Device, by adding the add x-forwarded header? I can see it is possible using FortiWeb, but not using Fortigate in the documentation.

 

Vinodh

1 Solution
Dave_Hall
Honored Contributor

None of the fgt devices we manage have web servers behind them, so not familiar any of those load-balancing options -- I was going to just post the same info Ede just posted, but figure I'll include the source material (on load-balancing) in case you need to do more than just enabling that one option...which btw is done via CLI to the VIP itself (not on a VIP group).  If you haven't set up anything fancy -- just port-forwarding to a single web server, you might be able to get away with disabling NAT on the firewall policy where you have the VIP set (WAN->web server).  Perhaps someone else can chime in here with a better solution.

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

View solution in original post

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
10 REPLIES 10
sarahP
New Contributor

Thanks a lot mhe 

 

Is it ok if I disable NAT? I afraid it may effects on our live service . 

And I have a weird problem. I have multiple websites with different domain names behind my FortiGate. Now even Nat is enabled on "WAN->webserver" policy, I enabled x-forwarder-for in Logformat in apache and then my web server can still get IP client for some websites/virtualhosts. 

- If client access via Cloudfront--> FortiGate --> Web server : can get client IP

- If client access to Fortigate direclty --> Web server: canNOT get client IP

- However, only one site which without via Cloudfront still can get client IP

 

Do you know why this happens? 

 

 

 

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors