Send the client IP to the origin in a header
Create a Request Phase rule that copies the client IP address into an X-Client-IP request header, so your origin receives that address alone.
You can send the Internet Protocol (IP) address of the client to your origin in a dedicated request header from Azion Console. A Request Phase rule in Rules Engine for Applications adds the header.
When a user sends a request to an application, the X-Forwarded-For header carries the client IP address. Azion’s distributed infrastructure mediates the requests to the application. The same header therefore also carries the other addresses in the route of the request. To isolate the client IP address, a rule forwards it in a header of its own.
Prerequisites
- An application that a workload delivers, with a rule that sends its requests to an origin. To create both, refer to Applications quickstart.
- Access to Azion Console. To sign in, refer to Access Azion Console.
Add the client IP address to a request header
The rule in this section adds an X-Client-IP header to the request that Azion sends to the origin. The header value is the ${remote_addr} variable, which holds the IP address of the client that sends the request. The rule matches every request, because every path starts with /.
To create the rule in Azion Console:
Access Azion Console > Applications > your application.
In the General section, enter a Name for the rule, such as client-ip-header.
In the Phase section, select Request Phase. The phase of a rule cannot change after you create the rule.
In the Criteria section, select ${uri} as the variable and starts_with as the operator.
Enter / as the argument.
In the Behaviors section, select Add Request Header.
Enter X-Client-IP:${remote_addr} as the argument of the behavior.
The rule appears in the Rules Engine tab, under Request. Each request that Azion sends to the origin carries the X-Client-IP header. Its value is the IP address of the client that originated the request.
Your application can already hold a Request Phase rule that matches every path, such as its rule that sends requests to an origin. That rule can carry the header instead of a new rule. A rule holds up to 10 behaviors.
To add the header to an existing rule in Azion Console:
Access Azion Console > Applications > your application, then select the Rules Engine tab.
Select the rule that matches every path. The Edit Rule drawer opens.
In the new behavior row, select Add Request Header.
Enter X-Client-IP:${remote_addr} as the argument of the behavior.
The rule keeps its other behaviors, and each request it matches reaches the origin with the X-Client-IP header.
The header name takes only letters, numbers, hyphens, and underscores. To send the address under another name, replace X-Client-IP in the argument. For the characters a header value accepts, refer to Add Request Header.