Guidelines
To write the XFF header on HTTPS packets, configure internal clients for an explicit proxy and HTTPS decryption.
- Configure internal clients to forward web traffic to the proxy's internal network interface or a PAC file.
- For transparent proxy deployments, the proxy must provide Man-in-the-Middle (MitM) decryption.
- For HTTPS decryption to work correctly, import your Secure Access root certificate to your proxy. For more information, see Manage Certificates. Also, refer to your proxy documentation.
Note: If you are not using XFF headers (and instead using SAML or only external IP addresses to identify sources), you only have to enable HTTPS decryption on the proxies deployed in your cloud environments.