In addition to XFF header usage in security
policy, you can view the XFF IP address in various logs, reports,
and the Application Command Center (ACC) to aid in monitoring and
troubleshooting. You can add the X-Forwarded-For column to Traffic,
Threat, Data Filtering, and Wildfire Submissions logs.
For
non-URL Filtering logs, XFF IP logging is supported only when packet
capture is not enabled.
The X-Forwarded-For IP column does not display a value in the threat logs if
the firewall detects a threat before it inspects the XFF header, however, it
is present in the traffic logs provided the action for the relevant security
profile is configured for Allow or
Alert.
To
view the XFF IP address in your logs, complete the following steps.