IIS Client IP Logging Behind a Reverse Proxy When a reverse proxy forwards requests to IIS, the standard Client IP Address ( Configure X-Forwarded-For in Your Reverse ProxyConfigure your reverse proxy to pass the original client IP address to IIS in the X-Forwarded-For request header. The setting depends on your proxy software; follow its documentation. The example below uses Nginx. If you use Nginx and it receives connections directly from clients, open your site's Nginx configuration file and add this directive to the existing This replaces any client-supplied X-Forwarded-For value with the connection's source IP address. The commonly used On Linux, test and reload the Nginx configuration: If a CDN, load balancer or another proxy sits in front of Nginx, configure trusted upstream addresses and client IP handling first; otherwise Add X-Forwarded-For to IIS LogsThe following steps use custom logging fields in IIS 8.5 and later. Configure logging at the website level; custom fields are unavailable when you select the server instead.
Verify X-Forwarded-For in IIS Logs Make a request through the proxy, then open the site's newest log file in the configured logging directory, usually Check that Here, If the column is missing, check the selected website's logging settings and the newest log file. If its value is Enable Client IP Detection in RdpGuardRun RdpGuard Dashboard as administrator, open the settings for HTTP or RD-WEB under Monitored protocols, then click Advanced settings.... The Advanced HTTP Settings dialog opens: ![]() Enable Read the client IP address from the X-Forwarded-For field. For HTTP protection, this option applies to IIS logs. When every request comes through the proxy, leave Use the connection IP address if X-Forwarded-For is missing unchecked: falling back to Reading the client IP does not change where blocking happens. A Windows Firewall rule for that IP will not stop a connection whose source address is the proxy. Block clients at the proxy, or configure IIS IP Address and Domain Restrictions with Proxy Mode and RdpGuard Custom Actions, as described in the HTTP protection and RD Web Access protection guides. | RdpGuard 10.4.5 Free Trial RdpGuard protects:
Our customers say "This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques "Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson "Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford "Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch "Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan "It's a great product - really stopping those RDP attackers :-)" - Dave, UK "First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes Our Other Products |