1. Home
  2. Security Hardening
  3. DISA STIG Apache Tomcat Application Server 9 V2R3
  4. TCAT-AS-000170 – Tomcat servers behind a proxy or load balancer must log client IP.

TCAT-AS-000170 – Tomcat servers behind a proxy or load balancer must log client IP.

Details

When running Tomcat behind a load balancer or proxy, default behavior is for Tomcat to log the proxy or load balancer IP address as the client IP. Desired behavior is to log the actual client IP rather than the proxy IP address. The RemoteIpValve logging component instructs Tomcat to grab the HTTP header X-Forwarded-For and use that for access logging.

Tomcat will identify 127.0.0.1, class A and class C RFC1918 addresses as internal proxy addresses; however, if the proxy has a routable IP or a class B private network address space (172.16.0.0/12), the user must also verify the ‘internalProxies setting is configured to reflect the proxy IP address.

Solution

From the Tomcat server as a privileged user:

Edit the $CATALINA_BASE/conf/server.xml file.

Only execute this first step if the proxy server is using a routable IP address or an RFC 1918 Class B address space: Add or edit the RemoteIpValve and configure the internalProxies setting to reflect the proxy addresses.

Modify the AccessLogValve and configure the requestAttributesEnabled setting = ‘True’.

EXAMPLE:

directory=’logs’
prefix=’access’
suffix=’.log’
pattern=’combined’
renameOnRotate=’true’
requestAttributesEnabled=’true’
/>

Restart Tomcat:
sudo systemctl restart tomcat
sudo systemctl tomcat daemon-reload

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Audit and Accountability.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles