AWS transfer: Changelog: source IP preservation for SFTP via NLB
Summary
Adds a change-history entry describing that SFTP servers behind a Network Load Balancer can use PROXY protocol v2 to preserve the client source IP, so IP-based access policies in custom identity providers see the real client address rather than the NLB private IP, and updates the latest-documentation date.
Security assessment
Documents a networking change ensuring client source IPs are preserved so IP-based access policies evaluate the true client address instead of the load balancer IP, avoiding misapplied network-based authorization. No CVE or incident is referenced.
Evidence
+Source IP preservation for SFTP servers behind a Network Load Balancer | AWS Transfer Family SFTP servers behind a Network Load Balancer (NLB) can use PROXY protocol v2 to preserve the client's source IP address. IP-based access policies in your custom identity provider then see the real client address instead of the NLB private IP. For details, see [Working with Network Load Balancers](./working-with-nlb.html). | September 15, 2026
Diff
diff --git a/transfer/latest/userguide/doc-history.md b/transfer/latest/userguide/doc-history.md index c44765fe8..a47488f3a 100644 --- a//transfer/latest/userguide/doc-history.md +++ b//transfer/latest/userguide/doc-history.md @@ -13 +13 @@ The following table describes the documentation for this release of AWS Transfer - * **Latest documentation update:** November 19, 2025 + * **Latest documentation update:** September 15, 2026 @@ -19,0 +20 @@ Change | Description | Date +Source IP preservation for SFTP servers behind a Network Load Balancer | AWS Transfer Family SFTP servers behind a Network Load Balancer (NLB) can use PROXY protocol v2 to preserve the client's source IP address. IP-based access policies in your custom identity provider then see the real client address instead of the NLB private IP. For details, see [Working with Network Load Balancers](./working-with-nlb.html). | September 15, 2026