Skip to content

forwarding Source IP as client IP #2

Description

@Rdago

When using spoa on Haproxy the modproxy logs keep showing that the connected client is the haproxy itself (which in my case is 127.0.0.1, as I run the agent on the server in a docker) and modproxy logs this IP.

Is there a way to include the original source IP which connected to the HAproxy beforehand and pass it to modsecurity - in a forwarded for header for example?

The problem is that some features like geoip or ip reputation do not work on this scenario. Moreover when using siem-solution for logging the modsecurity logs and threats the connecting IP is always localhost.

Im looking forward to receive some tipps or even a solution how to handle this.

Thanks in advance.

Activity

  1. jessequinn commented on Jul 11, 2022

    @jessequinn

    yah just ran into this now. basically white listing cannot work???? @Rdago did you find a solution?

  2. jessequinn commented on Jul 11, 2022

    @jessequinn

    @Rdago i see your forked the repo and made some changes. But did you fix the forwardfor? I see something about UniqueID.

  3. amitnarwal-sec commented on Jul 18, 2022

    @amitnarwal-sec

    @jessequinn I am also having the same issue, have you got any solution? how to get client-IP back on Modsecurity.

  4. mario-almeida commented on Oct 9, 2022

    @mario-almeida

    I am also having the same issue, is there any solution for this?

  5. evasokolova1f commented on Oct 20, 2022

    @evasokolova1f

    I also have the same problem. Any solution?

  6. CorentinS6 commented on Oct 20, 2022

    @CorentinS6

    same problem here.

    the trick i use to match requests in haproxy and modsec is the uniqid header.

    in /etc/haproxy/haproxy.cfg, add this in frontend section :

    	# Add unique-id Header
    	unique-id-format %{+X}o\ %ci:%cp_%fi:%fp_%Ts_%rt:%pid
    	unique-id-header X-Unique-ID
    

    and modify this in default section :

    	#option	httplog
    	log-format "%ci:%cp [%tr] %ft %b/%s %TR/%Tw/%Tc/%Tr/%Ta %ST %B %CC %CS %tsc %ac/%fc/%bc/%sc/%rc %sq/%bq %hr %hs %{+Q}r %ID"
    

    Regards

  7. amitnarwal-sec commented on Oct 21, 2022

    @amitnarwal-sec

    Thank you @CorentinS6 It solved the problem.

  8. styelz commented on Jun 18, 2025

    @styelz

    Hi, this worked for me

    unique-id-format "%{+X}o\ %ci:%cp_%fi:%fp_%Ts_%rt:%pid client-ip:%[src]"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions