Client source IP address tracking
Configure client source IP address tracking for sessions
add authorization policy <policy_name> <expression> <action>
add lb vserver <LB_VS> HTTP <LB-VIP> <PORT> -AuthenticationHost <AUTH_VIP> -Authentication ON
add authentication vserver <AUTH_VS> SSL <Auth-VIP> <PORT>
add authorization policy validateClientIP "AAA.USER.SOURCEIP.EQ(CLIENT.IP.SRC).NOT" DENY
bind lb vserver <LB_VS> -policy validateClientIP -priority 1
Client IP address validation using X-Forwarded-For (XFF) in AAA sessions
Benefits
-
Stronger session integrity: Enforces security even when traffic passes through intermediate devices.
-
Modern topology support: Ideal for AAA deployments behind NAT or proxy devices.
-
Reduced attack surface: Significantly lowers the risk of session hijacking by preventing session reuse from different client networks.
Prerequisites
-
Trusted proxy infrastructure.
-
Proper responder or authorization policies configured on Gateway or AAA.
How it works
Key policy expressions
-
AAA.USER.XFFIP: Exposes the stored XFF IP address. -
AAA.USER.XFFIPV6: Exposes the stored XFF IPv6 address. -
AAA.USER.VALIDATE_CLIENTIP: A boolean expression that compares the XFF IP address stored at authentication with the one seen during access. If no XFF information is available, it automatically falls back to a source IP address comparison.
Configuration examples
-
SOURCE_IP based protection:
add authorization policy session_hijack_Block "AAA.USER.SOURCEIP.NE(CLIENT.IP.SOURCE)" DENY
AAA.USER.SOURCEIP.NE(CLIENT.IP.SOURCE)
-
XFF based protection:
add authorization policy session_hijack_Block "AAA.USER.XFFIP.NE(CLIENT.IP.SOURCE)" DENY
AAA.USER.XFFIP.NE(CLIENT.IP.SOURCE)
-
Using the VALIDATE_CLIENTIP expression:
add authorization policy session_hijack_Block "AAA.USER.VALIDATE_CLIENTIP.NOT" DENY
AAA.USER.VALIDATE_CLIENTIP.NOT
Limitations
-
Session cookie theft from the same client IP address cannot be detected.
-
Replayed or forged XFF headers might bypass validation.
-
XFF tampering can result in denial-of-service for valid users.
-
This feature reduces risk but does not eliminate all hijacking scenarios.