Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

希望在获取真实源IP的功能上,能针对不同域名单独设置,并且对XFF链提供从左或从右获取具体第几个IP的功能 #448

Closed
fankejing-just opened this issue Nov 17, 2023 · 1 comment
Labels
duplicate This issue or pull request already exists enhancement New feature or request

Comments

@fankejing-just
Copy link

背景与遇到的问题

访问在到达雷池WAF之前,经过了多层代理(包括但不限于恶意攻击多层跳板、CDN、云WAF、流量清洗等),因此XFF链非常长,而目前雷池只支持读取XFF最后一个IP地址(最右边),导致很请求源IP获取不正常。

建议的解决方案

建议增加按防护域名分别设置获取源IP的方式,同时提供对获取XFF链的方向(从左或从右)自定义功能按钮,如果能实现获取XFF链上第几个IP,那自然是更好的。

@fankejing-just fankejing-just changed the title 希望在获取真实源IP的功能上,能针对不同域名单独设备,并且对XFF链提供从左或从右获取具体第几个IP的功能 希望在获取真实源IP的功能上,能针对不同域名单独设置,并且对XFF链提供从左或从右获取具体第几个IP的功能 Nov 17, 2023
@Lorna0
Copy link
Collaborator

Lorna0 commented Nov 17, 2023

duplicate:

由于代理链路太长的情况不是很符合社区版的定位,加上 XFF 配置想要做好的话其实挺复杂(参考 #301 (comment) ),暂时还有一些争议,建议集中到上面的 issue 中讨论

@Lorna0 Lorna0 added duplicate This issue or pull request already exists enhancement New feature or request labels Nov 17, 2023
@Lorna0 Lorna0 closed this as not planned Won't fix, can't repro, duplicate, stale Nov 17, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
duplicate This issue or pull request already exists enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants