✔ Zcaler affects on ISLG
Completed by Morgan M.
- Assigned to
-
Jitesh D.
Ketan S.
Ryan K.
- Notes
-
We received the following message from one of our clients:
--------------
Good afternoon,Please be aware that in the coming months, a program of works has been initiated to implement a localised internet breakout point for all DLA Piper sites. To secure this new architecture, DLA Piper will be using Zscaler to protect our Business when interacting with Internet based services.In order to identify DLA Piper to Internet based service providers; the aim is to utilise X-Forwarded-For (XFF) headers to identify DLA Piper to Service providers when access online resources.As such, please can you confirm that you can support this approach in order for DLA Piper and advise if any interaction is required to the service your organisation provides for these changes to take effect.Kind Regards
--------------
Could you please determine whether the use of X-Forwarded-For (XFF) headers will affect the client's users from accessing and using ISLG.
Thanks,
Morgan
Could I get your feedback on the issue above.
Thanks,
Morgan
My apologies for the delayed response. Unfortunately this is outside my expertise, but based on some research it helps to confirm the originating IP address.
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Forwarded-For
Thanks!
Ryan
Morgan
The client above has requested that we provide them with more information on the above. Could you please provide your assessment as soon as possible.
Thanks,
Morgan
Yes, X-Forwarded-For (XFF) headers used for identifying the originating IP address of a client connecting to a web server through an HTTP proxy. To see the original IP address of the client, the X-Forwarded-For request header is used and We have implemented this approach in ISLG Rebuild and ILG as current implemented technology structure of ISLG and ILG provide benefit to do this features. We are looking into ISLG old application and update you once done.
Thanks,
Jitesh
Thanks,
Morgan
I'm following up on my comment above.
Thanks,
Morgan
It will not effect ISLG existing application as XFF headers will useful to getting original IP address of user if user going to access other network and server.
We will do XFF header implementation in old application and update you.
There is no impact to user but yes admin can take original IP address of user who accessing application whether user will use his or other network.
Thanks,
Jitesh
Morgan
I've notified the client that we're making the necessary XFF header implementation to the current ISLG application. Please let me know when those updates and complete.
Thanks,
Morgan
Could you please provide an update on implementing XFF headers into the current application.
Thanks,
Morgan