<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting Client IP with RD Gateway and Load Balancer in Protecting Applications</title>
    <link>https://community.cisco.com/t5/protecting-applications/getting-client-ip-with-rd-gateway-and-load-balancer/m-p/4880440#M2139</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;I’m currently working on a new RDS farm with duo MFA and using HAProxy to pass connections to RD Gateway Servers.&lt;/P&gt;
&lt;P&gt;The chain is something like this:&lt;BR /&gt;
Client → HAProxy → RD-Gateway → RD-Host&lt;/P&gt;
&lt;P&gt;Everything so far is working, however I can’t figure out how to pass the original Client IP to the RD-Gateway and/or DUO.  Since all connections are identified as the proxy IP address, it’s not possible to differentiate clients or use whitelisting features.  On top of that, the DUO Push notification will always list the client location as the HAProxy’s IP address.&lt;/P&gt;
&lt;P&gt;I’ve searched all over the DUO forums as well as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Duo Doco&lt;/LI&gt;
&lt;LI&gt;HAProxy/Aloha doco&lt;/LI&gt;
&lt;LI&gt;F5 load balancer doco&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The only thing even remotely close I can find is an old post from 2016 here which went unanswered:&lt;/P&gt;&lt;ASIDE class="quote quote-modified" data-post="1" data-topic="3494"&gt;
  &lt;DIV class="title"&gt;
    &lt;DIV class="quote-controls"&gt;&lt;/DIV&gt;
    &lt;IMG width="20" height="20" src="https://community.cisco.com/legacyfs/online/ciscoduo/letters/k_e19b73.png" style="display : inline;" /&gt;
    &lt;A href="https://community.duo.com/t/duo-for-rds-gateway-behind-load-balancer/3494"&gt;DUO for RDS Gateway behind load balancer&lt;/A&gt; &lt;A class="badge-wrapper  bullet" href="https://community.cisco.com/c/protecting-applications-forum/20"&gt;&lt;SPAN class="badge-category-bg" style="background-color: #F7941D;"&gt;&lt;/SPAN&gt;&lt;SPAN style="" data-drop-close="true" class="badge-category clear-badge" title="Duo helps you reduce risks by setting and enforcing policies and app access. Visit the forum for Q-and-A on access policies."&gt;Protecting Applications forum&lt;/SPAN&gt;&lt;/A&gt;
  &lt;/DIV&gt;
  &lt;BLOCKQUOTE&gt;
    Hi, 
We are currently running an HAProxy infront of 2 RDS Gateways, and are using DUO authentication for RDS Gateway. 
As expected when we connect through the HAProxy to the RDS Gateways, the client IP address isnt forwarded, and all the clients are listed as connected with the HAProxy IP address. 
This is expected. 
We want to be able to forward the Client IP address to the RDS Gateway, which ofcourse isnt DUOs “fault”, that its not happening be default. 
But wanted to reach out, and hear anyon…
  &lt;/BLOCKQUOTE&gt;
&lt;/ASIDE&gt;

&lt;P&gt;Any thoughts?&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 01 Aug 2019 03:56:49 GMT</pubDate>
    <dc:creator>lateralplains</dc:creator>
    <dc:date>2019-08-01T03:56:49Z</dc:date>
    <item>
      <title>Getting Client IP with RD Gateway and Load Balancer</title>
      <link>https://community.cisco.com/t5/protecting-applications/getting-client-ip-with-rd-gateway-and-load-balancer/m-p/4880440#M2139</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;I’m currently working on a new RDS farm with duo MFA and using HAProxy to pass connections to RD Gateway Servers.&lt;/P&gt;
&lt;P&gt;The chain is something like this:&lt;BR /&gt;
Client → HAProxy → RD-Gateway → RD-Host&lt;/P&gt;
&lt;P&gt;Everything so far is working, however I can’t figure out how to pass the original Client IP to the RD-Gateway and/or DUO.  Since all connections are identified as the proxy IP address, it’s not possible to differentiate clients or use whitelisting features.  On top of that, the DUO Push notification will always list the client location as the HAProxy’s IP address.&lt;/P&gt;
&lt;P&gt;I’ve searched all over the DUO forums as well as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Duo Doco&lt;/LI&gt;
&lt;LI&gt;HAProxy/Aloha doco&lt;/LI&gt;
&lt;LI&gt;F5 load balancer doco&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The only thing even remotely close I can find is an old post from 2016 here which went unanswered:&lt;/P&gt;&lt;ASIDE class="quote quote-modified" data-post="1" data-topic="3494"&gt;
  &lt;DIV class="title"&gt;
    &lt;DIV class="quote-controls"&gt;&lt;/DIV&gt;
    &lt;IMG width="20" height="20" src="https://community.cisco.com/legacyfs/online/ciscoduo/letters/k_e19b73.png" style="display : inline;" /&gt;
    &lt;A href="https://community.duo.com/t/duo-for-rds-gateway-behind-load-balancer/3494"&gt;DUO for RDS Gateway behind load balancer&lt;/A&gt; &lt;A class="badge-wrapper  bullet" href="https://community.cisco.com/c/protecting-applications-forum/20"&gt;&lt;SPAN class="badge-category-bg" style="background-color: #F7941D;"&gt;&lt;/SPAN&gt;&lt;SPAN style="" data-drop-close="true" class="badge-category clear-badge" title="Duo helps you reduce risks by setting and enforcing policies and app access. Visit the forum for Q-and-A on access policies."&gt;Protecting Applications forum&lt;/SPAN&gt;&lt;/A&gt;
  &lt;/DIV&gt;
  &lt;BLOCKQUOTE&gt;
    Hi, 
We are currently running an HAProxy infront of 2 RDS Gateways, and are using DUO authentication for RDS Gateway. 
As expected when we connect through the HAProxy to the RDS Gateways, the client IP address isnt forwarded, and all the clients are listed as connected with the HAProxy IP address. 
This is expected. 
We want to be able to forward the Client IP address to the RDS Gateway, which ofcourse isnt DUOs “fault”, that its not happening be default. 
But wanted to reach out, and hear anyon…
  &lt;/BLOCKQUOTE&gt;
&lt;/ASIDE&gt;

&lt;P&gt;Any thoughts?&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 01 Aug 2019 03:56:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/protecting-applications/getting-client-ip-with-rd-gateway-and-load-balancer/m-p/4880440#M2139</guid>
      <dc:creator>lateralplains</dc:creator>
      <dc:date>2019-08-01T03:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Client IP with RD Gateway and Load Balancer</title>
      <link>https://community.cisco.com/t5/protecting-applications/getting-client-ip-with-rd-gateway-and-load-balancer/m-p/4880441#M2140</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;I think you would like The Duo RDG application to pass X-Forwarded-For as the client IP? This is not supported today, but you can contact your Duo account executive or customer success manager if you are working with one, or Duo Support, and ask to be added to the feature request for this.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Aug 2019 14:24:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/protecting-applications/getting-client-ip-with-rd-gateway-and-load-balancer/m-p/4880441#M2140</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2019-08-02T14:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Client IP with RD Gateway and Load Balancer</title>
      <link>https://community.cisco.com/t5/protecting-applications/getting-client-ip-with-rd-gateway-and-load-balancer/m-p/4880442#M2141</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi DuoKristina,&lt;/P&gt;
&lt;P&gt;Cheers for the response.  This is in essence what I’d like to do.  If I knew where the RDG Application derived the Client IP from then I could look into a way of munging the necessary headers to get that working.&lt;/P&gt;
&lt;P&gt;The only things I’ve been able to discover is MS has their own ISA (forefront) system which “somehow” achieves this functionality and passes the original client IP into the RD Gateway Manager.  However I can’t really find any documentation on the protocol or how it achieves it.&lt;BR /&gt;
Alternatively, it may work if the proxy is configured in full passthrough mode, which requires the RD Gateway server to use the proxy as it’s gateway, which brings a whole host of issues with it.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 05 Aug 2019 06:27:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/protecting-applications/getting-client-ip-with-rd-gateway-and-load-balancer/m-p/4880442#M2141</guid>
      <dc:creator>lateralplains</dc:creator>
      <dc:date>2019-08-05T06:27:37Z</dc:date>
    </item>
  </channel>
</rss>

