IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  AWS

    Posted Thu May 14, 2020 08:46 PM
    We have several ISAM appliances running in AWS cloud being feed by Network load Balancers
    A requirement is to pass the client IP. AWS has something called Proxy Protocal version 2
    Im interested in knowing if anyone has used the protocol and how ISAM would recoginize the header being passed on

    ------------------------------
    Robert Wehrle
    Architect
    PPSInfotech
    Cary NC
    9193684348
    ------------------------------


  • 2.  RE: AWS

    Posted Wed August 18, 2021 03:57 PM
    I stumbled upon this post being a year old. However,  to (hopefully) finalize this thread: You can configure the TargetGroups attached to a NLB to preserve client IPs. See  "Client IP preservation" section here: https://docs.aws.amazon.com/elasticloadbalancing/latest/network/load-balancer-target-groups.html 

    Hope this is helpful to anyone.

    Regards,
    Stefan

    ------------------------------
    Stefan Jurack
    ------------------------------



  • 3.  RE: AWS

    Posted Wed June 14, 2023 09:01 AM
    Edited by Sarfaraz Khan Mon June 19, 2023 06:46 AM

    The Proxy Protocol version 2 in AWS allows passing client IP information to backend servers, such as the ISAM (IBM Security Access Manager) appliances, when using Network Load Balancers (NLBs). It enables the ISAM appliances to recognize the header containing the client IP.

    To implement this requirement, you would need to configure your NLB to include the Proxy Protocol header while forwarding the client requests to the ISAM appliances. This header contains the client IP information.

    Regarding ISAM's recognition of the header being passed on, ISAM supports the Proxy Protocol version 2 and can process the header to extract the client IP. By enabling Proxy Protocol support on the ISAM appliances, they will be able to decode the header and retrieve the client IP information for further processing or logging purposes.

    To ensure proper integration, it is recommended to consult the documentation provided by both AWS and IBM for detailed configuration instructions and compatibility requirements. These resources can provide specific guidance on how to configure the NLB and ISAM appliances to work together seamlessly, allowing the ISAM appliances to recognize and extract the client IP from the Proxy Protocol header.



    ------------------------------
    Sarfaraz Khan
    ------------------------------