AWS Transfer Family now preserves the client’s source IP address using Proxy Protocol v2 (PPv2) when you place a Network Load Balancer (NLB) in front of your SFTP server that uses a VPC-hosted endpoint. You can now retain visibility of the client’s source IP for IP-based auditing, access controls, and compliance when you use your own NLB.
Previously, an NLB replaced the client’s source IP with its own private IP address, so your Transfer Family logs and events recorded the NLB’s address instead of the client’s source IP. Because the NLB’s private IP was the address presented to your custom identity provider during authentication, you couldn’t authorize users based on their true source IP. With this launch, you can enable source IP preservation on your SFTP server so that the client’s source IP is preserved. The preserved source IP is recorded in your logs and events and presented to your custom identity provider during authentication. You can enable the feature on each Transfer Family server individually through the console, CLI, or API.
Source IP preservation for SFTP servers is available in all AWS Regions where AWS Transfer Family is available. To get started, visit the AWS Transfer Family console or use the AWS CLI/SDK. To learn more, visit the Transfer Family User Guide.
Categories: general:products/aws-transfer-family,marketing:marchitecture/storage,marketing:marchitecture/migration,general:products/amazon-elastic-load-balancing
Source: Amazon Web Services


