Software Secure Access
Activity Manage

Cisco Secure Access Help Manage Proxy Chaining Forwarded-For (XFF) Configuration

Last updated: Aug 20, 2025

Forwarded-For (XFF) Configuration

You can configure the X-Forwarded-For (XFF) request header by using an on-premises proxy or a browser plugin such as Firefox's Simple Modify Headers plugin.

When configured, the XFF header sets the internal IP address for traffic on a Registered Network (an egress IP). You must add these Registered Networks as sources in your internet access rules. Then, for traffic on the Registered Networks, the Activity Search report includes the internal IP addresses.

Note: Cisco Secure Access does not require the XFF header for deploying proxy chaining.