ConceptsNetworking, domains & TLS
The headers that your app gets
The proxy removes the address headers that a client sends and sets its own, thus your app can trust them.
A client sends a request with a false header: X-Forwarded-For: 1.2.3.4.
1 / 4
The proxy is the edge of your server. It removes these headers of the client: Forwarded, each X-Forwarded-*, X-Real-IP, X-Client-IP and similar headers. Then it sets its own.
The headers that the proxy sets
| Header | Value |
|---|---|
Host | The host that the client asked for, with the port. |
X-Forwarded-For | The IP address of the client only (no chain). |
X-Real-IP | The IP address of the client. |
X-Forwarded-Proto | http or https. |
X-Forwarded-Host | Same as Host. |
X-Forwarded-Port | The port in the URL that the client used, else 80 or 443. |
Forwarded | The same facts in RFC 7239 form: for=…;host=…;proto=…. |
X-Request-Id | A random id, unless the request has one. |
Try it
curl -H 'X-Forwarded-For: 1.2.3.4' http://echo.localhost:8080/The app does not get the false header:
{
"host": "echo.localhost:8080",
"x-forwarded-for": "127.0.0.1",
"x-forwarded-proto": "http",
"x-forwarded-host": "echo.localhost:8080",
"x-forwarded-port": "8080",
"x-real-ip": "127.0.0.1",
"forwarded": "for=127.0.0.1;host=\"echo.localhost:8080\";proto=http",
"x-request-id": "59f1d9afbc7b4c7f9dda561433c3ab9b"
}- The proxy does not change the headers that a CDN sets, such as
CF-Connecting-IPorTrue-Client-IP. - If a CDN or a second reverse proxy is in front of Ferry,
X-Forwarded-Forhas the address of that proxy. X-Forwarded-Protoishttpwhen that proxy connects to Ferry with plain HTTP.
See Production setup.