<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Suricata block X-Forwarded-For IPs]]></title><description><![CDATA[<p dir="auto">Greetings all,</p>
<p dir="auto">According to the Suricata docs (http://suricata.readthedocs.io/en/suricata-4.0.0/), the eve-log and and unified2-alert output plugins support overwriting the source or destination IP (depending on flow direction) with the IP address obtained from the X-Forwarded-For HTTP header.  It is enabled by adding the necessary xff params to the output plugin configurations.  This is useful when Suricata is inspecting traffic for a Web server behind a reverse proxy, especially when you want to offload SSL at the reverse proxy so Suricata can inspect the decrypted traffic.  The xff functionality in Suricata avoids having to use a more complicated transparent reverse proxy in order to inspect SSL traffic.</p>
<p dir="auto">For alerts, can Suricata be configured to block IPs in pfSense obtained from the X-Forwarded-For header?</p>
<p dir="auto">Thank you</p>
]]></description><link>https://forum.netgate.com/topic/124630/suricata-block-x-forwarded-for-ips</link><generator>RSS for Node</generator><lastBuildDate>Sat, 07 Mar 2026 14:53:22 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/124630.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 18 Dec 2017 22:10:46 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Suricata block X-Forwarded-For IPs on Tue, 19 Dec 2017 00:42:04 GMT]]></title><description><![CDATA[<p dir="auto">No, Suricata on pfSense can't do that (block the X-Forwarded-For address).</p>
<p dir="auto">Bill</p>
]]></description><link>https://forum.netgate.com/post/741789</link><guid isPermaLink="true">https://forum.netgate.com/post/741789</guid><dc:creator><![CDATA[bmeeks]]></dc:creator><pubDate>Tue, 19 Dec 2017 00:42:04 GMT</pubDate></item></channel></rss>