Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Juniper Security Director Cloud User Guide
Table of Contents Expand all
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

Configure Trusted Proxy Servers

date_range 22-Jun-22

Use this page to add trusted proxy server IP addresses to Juniper ATP Cloud. This feature is optional

Access this page from Shared Services > ATP > Misc Configuration > Proxy Servers.

When there is a proxy server between users on the network and a firewall, the firewall might see the proxy server IP address as the source of an HTTP or HTTPS request instead of the actual address of the user making the request.

With this in mind, X-Forwarded-For (XFF) is a standard header added to packets by a proxy server that includes the real IP address of the client making the request. Therefore, if you add trusted proxy servers IP addresses to the list in Juniper ATP Cloud, by matching this list with the IP addresses in the HTTP header (X-Forwarded-For field) for requests sent from Juniper Secure Edge, Juniper ATP Cloud can determine the originating IP address.

Note:

X-Forwarded-For (XFF) only applies to HTTP or HTTPS traffic, and only if the proxy server supports the XFF header.

To add trusted proxy servers to the list, do the following:

  1. Navigate to Shared Services > ATP > Misc Configuration > Proxy Servers.

  2. Click the + sign.

  3. Enter the IP address of the proxy server in the available field.

  4. Click OK.

footer-navigation