cancel
Showing results for 
Search instead for 
Did you mean: 

SA 4000 External ip address in header(?)

its_
New Contributor

SA 4000 External ip address in header(?)

Hi, anybody know if it is possible to keep the original client ip in the packets going trough the SA 4000, we got a app behind the SA box that needs to log the original client ip instead of the SA:boxes ip.

I haven't looked at the app myself yet, i only got a developer saying that he can't get the original client ip...

/Daniel

2 REPLIES 2
kenlars_
Super Contributor

Re: SA 4000 External ip address in header(?)

Of course, you would then be seeing the virtual (NC) address as the source of the packets, and not the native address of the remote PC.

Ken

firewall72_
Frequent Contributor

Re: SA 4000 External ip address in header(?)

Hi,

The SA will rewrite the traffic by default.  What you could do is configure a do not rewrite policy for that App and use Network Connect to tunnel the traffic.  This will then use the source IP of the remote machine instead of the SA.  Just a thought...

John





John Judge
JNCIS-SEC, JNCIS-ENT,

If this solves your problem, please mark this post as "Accepted Solution". Kudos are appreciated.