# Send the client IP to the origin in a header

You can send the Internet Protocol (IP) address of the client to your origin in a dedicated request header from Azion Console. A Request Phase rule in [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine/) adds the header.

When a user sends a request to an [application](/en/documentation/platform/applications/), the `X-Forwarded-For` header carries the client IP address. Azion's distributed infrastructure mediates the requests to the application. The same header therefore also carries the other addresses in the route of the request. To isolate the client IP address, a rule forwards it in a header of its own.

---

## Prerequisites

- An application that a [workload](/en/documentation/platform/workloads/) delivers, with a rule that sends its requests to an origin. To create both, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).
- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

---

## Add the client IP address to a request header

The rule in this section adds an `X-Client-IP` header to the request that Azion sends to the origin. The header value is the `${remote_addr}` variable, which holds the IP address of the client that sends the request. The rule matches every request, because every path starts with `/`.

To create the rule in Azion Console:

1. **Open the application**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**.

2. **Select the Rules Engine tab**

3. **Select + Rule**

4. **Name the rule**

   In the **General** section, enter a **Name** for the rule, such as `client-ip-header`.

5. **Select Request Phase**

   In the **Phase** section, select **Request Phase**. The phase of a rule cannot change after you create the rule.

6. **Set the criterion**

   In the **Criteria** section, select `${uri}` as the variable and `starts_with` as the operator.

7. **Enter the path**

   Enter `/` as the argument.

8. **Add the header behavior**

   In the **Behaviors** section, select **Add Request Header**.

9. **Enter the header**

   Enter `X-Client-IP:${remote_addr}` as the argument of the behavior.

10. **Select Save**

The rule appears in the **Rules Engine** tab, under **Request**. Each request that Azion sends to the origin carries the `X-Client-IP` header. Its value is the IP address of the client that originated the request.

Your application can already hold a Request Phase rule that matches every path, such as its rule that sends requests to an origin. That rule can carry the header instead of a new rule. A rule holds up to 10 behaviors.

To add the header to an existing rule in Azion Console:

1. **Open the Rules Engine tab**

   Access [Azion Console](https://console.azion.com/) > **Applications** > **your application**, then select the **Rules Engine** tab.

2. **Open the rule**

   Select the rule that matches every path. The **Edit Rule** drawer opens.

3. **Select + Add Behavior**

4. **Add the header behavior**

   In the new behavior row, select **Add Request Header**.

5. **Enter the header**

   Enter `X-Client-IP:${remote_addr}` as the argument of the behavior.

6. **Select Save**

The rule keeps its other behaviors, and each request it matches reaches the origin with the `X-Client-IP` header.

The header name takes only letters, numbers, hyphens, and underscores. To send the address under another name, replace `X-Client-IP` in the argument. For the characters a header value accepts, refer to [Add Request Header](/en/documentation/platform/applications/rules-engine/#add-request-header).

---

## Next steps

- [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine.md#variables): Every variable a rule can read, such as the client port, the request method, and the geolocation of the client.
- [Create request and response rules](/en/documentation/guides/application-development/getting-started/rules-engine.md): Create rules for the Request Phase and the Response Phase of an application.
- [Connectors](/en/documentation/platform/connectors.md): How an application reaches the origin that receives the header.
- [Debug rules created with Rules Engine](/en/documentation/guides/application-development/getting-started/debug-rules.md): Find out whether a rule ran on a request, through the GraphQL API, Data Stream, or Real-Time Events.
