Client-IP behind Web Application Firewall (WAF)
Nowadays it is common to use a Web Application Firewall (WAF) upstream the Webserver. In this case some security features like Hacker IP are not usable.
It should be possible to get the real client-ip within the use of a WAF.
We provide the X-FORWARDED-FOR and X-REAL-IP Header for this case.

Log in to comment and vote
Comments4
Claudio Pereria
Jul 12
Has anyone managed to get this functionality working?
I have an nginx proxy manager running as a reverse proxy, and it sends the X-Forward-For flag correctly. However, even with everything checked in the Security settings of the web interface, TSPlus doesn't pass the correct IP to Advanced Security!
In all my tests, I keep getting the nginx proxy manager's IP blocked, not the attacker's real IP.
I'm testing with TSPlus 19.40.7.9 and Advanced Security 7.5.6.23.
If anyone has managed to get it working and can give me some advice, I would greatly appreciate it.
Claudio Pereria
Jun 9
I just received an email informing me that this feature has been completed and will be added to Advanced Security, which makes me very happy! I would like to know the minimum version of TSPlus and Advanced Security required for this feature to be active and work correctly.
I would appreciate it if someone could provide me with this information so that I can set up a lab before deploying it to my production environment!
Timo Henkel
Feb 26
I have the same problem and am looking for a way to use X-Forwarded-For
Claudio Pereria
Feb 5
I'm having the same problem! I'm studying but can't use Advanced Security in my environment because I work with a reverse proxy, since we have several applications that need port 443 and to facilitate the deployment of valid HTTPS certificates for multiple services.
I've been researching for a few days and haven't found anything that can be used; everything I've found so far hasn't worked.
Using Process Monitor software, apparently the HTML5service is what receives the IP and logs it in the rdp_log.txt file, and it seems that's where the blocking is done.
If I'm wrong, no problem, but it would be helpful if TSPlus had an option in the Advanced section called "Get Real IP," which would be the IP returned by X-Forward-For, for cases like ours.