【MVS】F5 BIG-IP LTM HTTP XFF头插入配置说明
F5 BIG-IP LTM虚服务配置SNAT时,客户端真实的源地址转换为F5设备上配置的地址,导致后端服务器无法获取真实的客户端地址,无法满足溯源等安全侧要求。可以在HTTP请求报文头中插入X-Forwarded-For字段来实现溯源功能,具体操作如下。
To configure the BIG-IP system to insert the original client IP address in an X-Forwarded-For HTTP header, perform the following procedure:
Note: Older versions of BIG-IP software may display the option as Insert XForwarded For instead of Insert X-Forwarded-For.
You must now associate the new HTTP profile with the virtual server.
实际操作效果如下:
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作