{"id":4989,"date":"2021-02-21T23:30:47","date_gmt":"2021-02-21T23:30:47","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=4989"},"modified":"2021-02-21T23:30:47","modified_gmt":"2021-02-21T23:30:47","slug":"iis-logs-reporting-gateway-ip-address-as-x-forwarded-for","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/iis-logs-reporting-gateway-ip-address-as-x-forwarded-for","title":{"rendered":"IIS logs reporting Gateway IP address as X-Forwarded-For"},"content":{"rendered":"<p>Recently was trying to disable access to a subfolder on an IIS site. Adding IP Restrictions to the site , and looking the Logs , the address of the requestor was coming up as the Gateway of the DMZ.<\/p><p>We need to use the X-forwarder-For header for this , however a need a WAF or application level firewall to do this stamping for us<\/p><p>After enabling Proxy Mode on Cloudflare for the hostname , the correct IP address starting populating for X-forwarder-For header so I could turn on blocking<\/p>","protected":false},"excerpt":{"rendered":"<p>Recently was trying to disable access to a subfolder on an IIS site. Adding IP Restrictions to the site , and looking the Logs , the address [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4989","post","type-post","status-publish","format-standard","hentry","category-research"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/4989","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=4989"}],"version-history":[{"count":1,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/4989\/revisions"}],"predecessor-version":[{"id":4990,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/4989\/revisions\/4990"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=4989"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=4989"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=4989"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}