<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic operation of the XFF Proxy function in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/operation-of-the-XFF-Proxy-function/m-p/229806#M44231</link>
    <description>&lt;P&gt;Hi guys.&lt;BR /&gt;We have a customer who is using the firewall as a non-transparent proxy and he shared with us some questions about the operation of XFF about which we did not find too much information published.&lt;BR /&gt;The first question is regarding the handling of XFF.&lt;BR /&gt;It is how to disable the output of the XFF header so that the proxy does not send the client's original IP to the destination server.&lt;BR /&gt;Can rules be configured in the firewall to identify the user or computer by the XFF content?&lt;BR /&gt;Can proxy Path be implemented in DNS so that DNS resolves to the proxy IP instead of an end server IP, redirecting traffic through that proxy for proper handling?&lt;/P&gt;</description>
    <pubDate>Tue, 15 Oct 2024 19:30:44 GMT</pubDate>
    <dc:creator>Agust</dc:creator>
    <dc:date>2024-10-15T19:30:44Z</dc:date>
    <item>
      <title>operation of the XFF Proxy function</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/operation-of-the-XFF-Proxy-function/m-p/229806#M44231</link>
      <description>&lt;P&gt;Hi guys.&lt;BR /&gt;We have a customer who is using the firewall as a non-transparent proxy and he shared with us some questions about the operation of XFF about which we did not find too much information published.&lt;BR /&gt;The first question is regarding the handling of XFF.&lt;BR /&gt;It is how to disable the output of the XFF header so that the proxy does not send the client's original IP to the destination server.&lt;BR /&gt;Can rules be configured in the firewall to identify the user or computer by the XFF content?&lt;BR /&gt;Can proxy Path be implemented in DNS so that DNS resolves to the proxy IP instead of an end server IP, redirecting traffic through that proxy for proper handling?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 19:30:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/operation-of-the-XFF-Proxy-function/m-p/229806#M44231</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2024-10-15T19:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: operation of the XFF Proxy function</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/operation-of-the-XFF-Proxy-function/m-p/229812#M44232</link>
      <description>&lt;P&gt;You can disable XFF by one of the two methods here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk100223" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk100223&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;You can perform inspection based on XFF as described here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Configuring-Identity-Awareness-Identifying-Users-behind-HTTP-Proxy-Server.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Configuring-Identity-Awareness-Identifying-Users-behind-HTTP-Proxy-Server.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I'm not familiar with implementing a proxy path in DNS.&lt;BR /&gt;You can forward all requests to a different proxy server by following:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk101395" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk101395&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Please note the known performance impact of operating in explicit proxy mode:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk92482" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk92482&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 20:03:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/operation-of-the-XFF-Proxy-function/m-p/229812#M44232</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-15T20:03:43Z</dc:date>
    </item>
  </channel>
</rss>

