Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Kaspars_Zibarts
Authority
Authority

HTTP XFF header not being removed in R80.10

In case someone else was using SK How to enable stripping of X-Forward-For (XFF) field 

I know that it worked perfectly OK in R70.30 and we never bothered checking it after upgrades to R80.10, just assumed it worked. Today just by pure chance I stumbled across the fact that our internal IPs are being sent out in XFF header that were supposed to be stripped out.

One thing that I noticed with R80.10 is that kernel parameter ws_remove_proxy_connection_header doesn't seem to work anymore 

Anyone else could verify this?

SR submitted

8 Replies
This widget could not be displayed.