Views:
When you implement the Zero Trust Internet Access Gateway Service, the user IP and geolocation is based on that of the Cloud gateway and not where your clients are located. The X-Forwarded-For header allows you to insert your own public IP address to the header for inspected HTTP/HTTPS traffic.
The X-Forwarded-For header is a global setting that applies to all of your Internet Access cloud gateways. including the cloud gateway
You have three options when setting up and managing your cloud gateways:
  • No change: This is the default setting. The cloud gateway does not change an X-Forwarded-For header.
  • Append or insert the public IP address connecting to the cloud gateway into X-Forwarded-For header: The cloud gateway, including default gateway for public/home network location, uses your connecting public IP address in the X-Forwarded-For header for inspected HTTP/HTTPS traffic. You must ensure that HTTPS inspection is turned on for traffic requiring this action.
  • Remove the X-Forwarded-For header: The cloud gateway, including the default gateway, removes the X-Forwarded-For header from inspected HTTP/HTTPS traffic. You must ensure that HTTPS inspection is turned on for traffic requiring this action.
To add an X-Forward-For header:

Procedure

  1. On the Trend Vision One console, go to Zero Trust Secure AccessSecure Access ConfigurationInternet Access and AI Service Access Configuration.
  2. On the Global Settings tab, click Cloud Gateway Advanced Setting.
  3. Select the appropriate radio button:
    • No change (Default)
    • Append or insert the public IP address connecting to the cloud gateway into the X-Forwarded-For header
    • Remove the X-Forwarded-For header