Symptom
One or more of the following situations is observed in SAP API Management:
- The Access Control policy is configured to allow only specific IP addresses, but requests from non-whitelisted IPs are still reaching the proxy when the caller sets an allowed IP address in the
X-Forwarded-For or True-Client-IP request header.
- A custom IP whitelisting solution is implemented using KeyValueMapOperations, JavaScript, and RaiseFault policies, but the validation can be bypassed because all available header values (X-Forwarded-For, True-Client-IP, client.ip) are either spoofable by the client or resolve to an internal load balancer IP.
- The Apigee variable client.resolved.ip is referenced in documentation or community content, but it is not available in SAP API Management and returns no value.
Read more...
Environment
- SAP Integration Suite
- API Management
Product
Keywords
ACCESS CONTROL, IP WHITELISTING, IP BYPASS, X-FORWARDED-FOR, TRUE-CLIENT-IP, VALIDATEBASEDON, IGNORETRUECLIENTIPHEADER, X_FORWARDED_FOR_LAST_IP, CLIENT.IP, CLIENT.RESOLVED.IP, SPOOFABLE HEADER, API PROXY, APIGEE, GEO-FENCING, API Management, SAP API Management, APIM, SAP Integration Suite, API Proxy, API Provider, Policy, Apigee
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview