How to Configure IIS and RdpGuard for X-Forwarded-For - Reverse Proxy Setup and Client IP Logging
RdpGuard
Intrusion prevention system for your Windows Server
 

IIS Client IP Logging Behind a Reverse Proxy

When a reverse proxy forwards requests to IIS, the standard Client IP Address (c-ip) field usually records the proxy's address. Configure your proxy to send the original client IP in X-Forwarded-For, add that header to the IIS log, then enable RdpGuard to read it for HTTP or RD Web Access protection.

Configure X-Forwarded-For in Your Reverse Proxy

Configure your reverse proxy to pass the original client IP address to IIS in the X-Forwarded-For request header. The setting depends on your proxy software; follow its documentation. The example below uses Nginx.

If you use Nginx and it receives connections directly from clients, open your site's Nginx configuration file and add this directive to the existing location block that proxies requests to IIS:

proxy_set_header X-Forwarded-For $remote_addr;

This replaces any client-supplied X-Forwarded-For value with the connection's source IP address. The commonly used $proxy_add_x_forwarded_for variable instead preserves the incoming header and appends an address. RdpGuard reads the first address in the logged value, so an untrusted client must not be allowed to supply that first address. See the Nginx proxy header documentation.

On Linux, test and reload the Nginx configuration:

sudo nginx -t && sudo nginx -s reload

If a CDN, load balancer or another proxy sits in front of Nginx, configure trusted upstream addresses and client IP handling first; otherwise $remote_addr will identify that upstream proxy. Nginx provides the real IP module for this purpose. Restrict direct access to IIS so requests cannot bypass your trusted proxy.

Add X-Forwarded-For to IIS Logs

The following steps use custom logging fields in IIS 8.5 and later. Configure logging at the website level; custom fields are unavailable when you select the server instead.

  1. Open IIS Manager, select your website in the Connections pane, then double-click Logging in the IIS feature group.

    IIS Manager feature view with Logging highlighted
    Open the website's Logging settings.
  2. The Logging page opens:

    IIS Logging settings with W3C format and the Select Fields button
    Use W3C format and click Select Fields.

    Select W3C in Format. Under Log Event Destination, use Log file only or Both log file and ETW event, so RdpGuard has a log file to read. Click Select Fields....

  3. In W3C Logging Fields, click Add Field...:

    W3C Logging Fields dialog with the Add Field button
    Add a custom field to the existing W3C fields.
  4. The Add Custom Field dialog opens:

    Add Custom Field with X-Forwarded-For as the field name and source, and Request Header as the source type
    Log the X-Forwarded-For request header under the same field name.

    Enter these values:

    • Field Name: X-Forwarded-For
    • Source Type: Request Header
    • Source: X-Forwarded-For

    Use this exact Field Name so RdpGuard can find the column. Click OK in both dialogs, then Apply in the Actions pane.

Verify X-Forwarded-For in IIS Logs

Make a request through the proxy, then open the site's newest log file in the configured logging directory, usually %SystemDrive%\inetpub\logs\LogFiles with a W3SVC... subfolder for each site. Files containing custom fields have _x appended to their names. Allow time for buffered entries to be written.

Check that #Fields: includes X-Forwarded-For and that the corresponding value is the client's IP address. This shortened W3C example shows the relationship between the two address fields:

#Fields: date time c-ip cs-method cs-uri-stem sc-status X-Forwarded-For
2026-09-30 10:15:00 192.0.2.10 GET /login 200 203.0.113.45

Here, 192.0.2.10 is the proxy recorded in c-ip, and 203.0.113.45 is the original client recorded in X-Forwarded-For. Your log may contain more columns; their order is defined by its own #Fields: line.

If the column is missing, check the selected website's logging settings and the newest log file. If its value is -, check that the request passed through the proxy and that the proxy sent the header.

Enable Client IP Detection in RdpGuard

Run RdpGuard Dashboard as administrator, open the settings for HTTP or RD-WEB under Monitored protocols, then click Advanced settings.... The Advanced HTTP Settings dialog opens:

Advanced HTTP Settings with X-Forwarded-For enabled and connection IP fallback disabled
Enable X-Forwarded-For for a website behind a trusted proxy.

Enable Read the client IP address from the X-Forwarded-For field. For HTTP protection, this option applies to IIS logs. When every request comes through the proxy, leave Use the connection IP address if X-Forwarded-For is missing unchecked: falling back to c-ip can cause the proxy itself to be blocked. Click OK, then Save in the protocol's settings.

Reading the client IP does not change where blocking happens. A Windows Firewall rule for that IP will not stop a connection whose source address is the proxy. Block clients at the proxy, or configure IIS IP Address and Domain Restrictions with Proxy Mode and RdpGuard Custom Actions, as described in the HTTP protection and RD Web Access protection guides.

RdpGuard 10.4.5 Free Trial

RdpGuard protects:

Our customers say

"This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques

"Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson

"Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford

"Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch

"Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan

"It's a great product - really stopping those RDP attackers :-)" - Dave, UK

"First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes

Our Other Products
Copyright © 2012-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.  Refund Policy.