# Source IP is missing in FTP log even with forwardfor

**URL:** <https://discourse.haproxy.org/t/source-ip-is-missing-in-ftp-log-even-with-forwardfor/9546>\
**Category:** Help!\
**Created:** [February 28, 2024, 4:10am UTC](https://discourse.haproxy.org/t/source-ip-is-missing-in-ftp-log-even-with-forwardfor/9546 "2024-02-28T04:10:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jakonhaproxy](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jakonhaproxy](https://discourse.haproxy.org/u/jakonhaproxy)\
**Post date:** [February 28, 2024, 4:10am UTC](https://discourse.haproxy.org/t/source-ip-is-missing-in-ftp-log-even-with-forwardfor/9546/1 "2024-02-28T04:10:58Z")

</div>

Require the source IP in all the FTP server log that is being proxied. But in spite of following the documentation on ‘option forwardfor’ in liste, frontend, backend I am not getting the source IP instead I see only the local proxy IP in all the FTP server logs. Please let me know whether I am missing something or kindly point me to any other faults that is causing this.

My config is as below

```auto
global
    log 127.0.0.1 local0 info
    chroot /var/lib/haproxy
    user haproxy
    group haproxy
    maxconn 2000

defaults
    log global
    mode tcp
    option tcplog
    retries 3
    # todo : fix this appropriately.
    timeout connect 60000
    timeout check 5000
    timeout client 60000
    timeout server 60000

#
# This sets up the admin page for HA Proxy at port 55002.
#
listen stats
    bind *:55002
    mode tcp
    option forwardfor
    stats enable
    stats realm haproxystats
    stats auth myadmin:mypass
    stats uri /ftpha

# This is for the initial connection and control traffic
frontend fe_ftp_control
    bind *:21
    option forwardfor
    default_backend ftp_server_pool

# Each of these frontends represent a server and its corresponding PASV ports we set
frontend fe_ftp_01
    bind *:70101-70300
    option forwardfor
    default_backend be_ftp_01

frontend fe_ftp_02
    bind *:70301-70600
    option forwardfor
    default_backend be_ftp_02

# Global backend for the ftp control traffic to find a server
backend ftp_server_pool
    option forwardfor if-none
    server ftp_01 10.10.10.111:3331 check port 3331 inter 10s rise 1 fall 2
    server ftp_02 10.10.10.222:3331 check port 3331 inter 10s rise 1 fall 2

# Backends for each of our FTP servers
backend be_ftp_01
    option forwardfor if-none
    server ftp_01 10.10.10.111 check port 3331 inter 10s rise 1 fall 2

backend be_ftp_02
    option forwardfor if-none
    server ftp_02 10.10.10.222 check port 3331 inter 10s rise 1 fall 2

```

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [February 28, 2024, 2:25pm UTC](https://discourse.haproxy.org/t/source-ip-is-missing-in-ftp-log-even-with-forwardfor/9546/2 "2024-02-28T14:25:23Z")

</div>

Forward For is a HTTP header, it therefore only works when using haproxy in HTTP mode (for HTTP traffic).  
You can’t do the same with FTP.

The proxy protocol could be used in theory, but this requires support in the ftp server (and I’m not sure this was every implemented by any FTP server software).

The other way is to make haproxy the default gateway and configure it in transparent mode. This is very complicated and requires iptables configurations etc, as such I’d avoid it.

---

<div class="post-metadata">

**Author:** ![jakonhaproxy](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jakonhaproxy](https://discourse.haproxy.org/u/jakonhaproxy)\
**Post date:** [February 28, 2024, 3:41pm UTC](https://discourse.haproxy.org/t/source-ip-is-missing-in-ftp-log-even-with-forwardfor/9546/3 "2024-02-28T15:41:12Z")

</div>

Thanks Lukas for taking time.

I am using java apacheFTP Mina (FTP Server). I have the source and be able to do some minimal changes if you could help at a high level (Not overconfident and also I understand the other risks here).

I saw in this example also they have referred to forwardfor hence I was thinking it would work.

> [@How can I make FTP Connection?](https://discourse.haproxy.org/t/how-can-i-make-ftp-connection/2355):
>
> Hello How can I make FTP Connection? This is conf file: global log 127.0.0.1 local0 log 127.0.0.1 local1 notice #log loghost local0 info maxconn 4096 chroot /var/lib/haproxy user haproxy group haproxy daemon #debug #quiet stats socket /var/lib/haproxy/stats defaults log global mode http option httplog option dontlognull retries 3 redispatch maxconn 2000 contimeout 5000 clitimeout 50000 srvtimeout 50000 listen stats bind \*:8080 mo…

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [February 28, 2024, 5:01pm UTC](https://discourse.haproxy.org/t/source-ip-is-missing-in-ftp-log-even-with-forwardfor/9546/4 "2024-02-28T17:01:54Z")

</div>

You can find the protocol documentation here, proxy protocol V1 is ASCII based, while V2 is binary encoded. Both will do the job:

> <https://github.com/haproxy/haproxy/blob/master/doc/proxy-protocol.txt>

I’m not sure that would be a “minimal change” though.

---

<div class="post-metadata">

**Author:** ![jakonhaproxy](https://avatars.discourse-cdn.com/v4/letter/j/85f322/32.png) [@jakonhaproxy](https://discourse.haproxy.org/u/jakonhaproxy)\
**Post date:** [February 28, 2024, 6:54pm UTC](https://discourse.haproxy.org/t/source-ip-is-missing-in-ftp-log-even-with-forwardfor/9546/5 "2024-02-28T18:54:38Z")

</div>

Thanks. Let me check this to see whether I can attempt this.

If I understand it correct, when it is configured for forwardfor - httpserver handles them. FTP Server doesn’t handle it though the information is forwarded as part of the header from the proxy to the nodes. Please confirm whether this understanding is correct?

Do you know of any sample/reference Java implementation (HTTPServer)?

~JAK

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [February 28, 2024, 7:38pm UTC](https://discourse.haproxy.org/t/source-ip-is-missing-in-ftp-log-even-with-forwardfor/9546/6 "2024-02-28T19:38:45Z")

</div>

ForwardFor is a HTTP header, more specifically `X-Forwarded-For`

> **[X-Forwarded-For - HTTP | MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Forwarded-For)**
>
> The X-Forwarded-For (XFF) request header is a de-facto standard header for identifying the originating IP address of a client connecting to a web server through a proxy server.

It’s added to the HTTP requests so the the backend server knows the IP address.

The proxy protocol of haproxy on the other works with all protocols, but needs specific implementation, because it is unrelated to the actual protocol (FTP in this case) ; it simple sends the IP informations (among others) before the real protocol begins.
