<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP XFF username in Application Control logs in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/48983#M9598</link>
    <description>&lt;P&gt;I am adding HFF only to HTTP on the proxy.&lt;/P&gt;&lt;P&gt;When IP is added, the security gateway can recognize it as "proxies source ip" but not the authenticated username.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Mar 2019 09:45:52 GMT</pubDate>
    <dc:creator>Alex_Shpilman</dc:creator>
    <dc:date>2019-03-28T09:45:52Z</dc:date>
    <item>
      <title>HTTP XFF username in Application Control logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/48955#M9589</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;I have a use case where users are sitting behind a 3rd party proxy which then forwards the traffic to the internet through a security gateway.&lt;/P&gt;&lt;P&gt;Application Control, Identity Awareness and XFF detection enabled.&lt;/P&gt;&lt;P&gt;When I insert the proxied client IP into the HTTP XFF, the security gateway recognizes it and all works as expected, the XFF stripped off properly on the out.&lt;/P&gt;&lt;P&gt;But I'd like to see the source user in the Application Control instead of (or in addition) the original IP.&lt;/P&gt;&lt;P&gt;When I re-write the username into the HTTP XFF, the security gateway doesn't recognize it, I tried different combinations but no luck.&lt;/P&gt;&lt;P&gt;I was able to achieve this a few years back in R77.10 or R77.20 but can't remember what exactly I did back then...&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 07:08:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/48955#M9589</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2019-03-28T07:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP XFF username in Application Control logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/48968#M9592</link>
      <description>&lt;P&gt;Alex,&lt;/P&gt;&lt;P&gt;you have to use IdentityAwarenessBlade and enable the XFF-support to match the XFF IPs to the real user names.&lt;/P&gt;&lt;P&gt;But this does not work for HTTPS connections, because I think the XFF-header is too encrypted and the firewall cannot read this. Except you're using HTTPS inspection.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="XFF_IdentityAwareness.PNG" style="width: 636px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/504iB92F95417A45BF73/image-size/large?v=v2&amp;amp;px=999" role="button" title="XFF_IdentityAwareness.PNG" alt="XFF_IdentityAwareness.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 08:30:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/48968#M9592</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-03-28T08:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP XFF username in Application Control logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/48983#M9598</link>
      <description>&lt;P&gt;I am adding HFF only to HTTP on the proxy.&lt;/P&gt;&lt;P&gt;When IP is added, the security gateway can recognize it as "proxies source ip" but not the authenticated username.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 09:45:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/48983#M9598</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2019-03-28T09:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP XFF username in Application Control logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/49044#M9610</link>
      <description>&lt;P&gt;Alex,&lt;/P&gt;&lt;P&gt;what are you saying?&lt;/P&gt;&lt;P&gt;With added XFF-header and IdentityAwareness configured like shown you are able to get the username.&lt;/P&gt;&lt;P&gt;This works in our environment.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 14:37:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/49044#M9610</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-03-28T14:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP XFF username in Application Control logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/49083#M9613</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Wolfgang,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Do you use AD query or Identity Collector?&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case, the real IP is visible through XFF, and there is an identity record for that IP (in PDP) but not reflected in the logs.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 19:18:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/49083#M9613</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2019-03-28T19:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP XFF username in Application Control logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/49089#M9615</link>
      <description>&lt;P&gt;We are using Identity collector.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 19:54:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTP-XFF-username-in-Application-Control-logs/m-p/49089#M9615</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-03-28T19:54:59Z</dc:date>
    </item>
  </channel>
</rss>

