AWS transfer: Add PROXY protocol config option for SFTP servers
Summary
Documents a new PROXY protocol configuration option available only for SFTP servers, which preserves client source IP addresses when the server sits behind an NLB with PROXY protocol v2 enabled. Also narrows the NLB/NAT gateway avoidance guidance to FTP and FTPS servers.
Security assessment
The added line documents a network configuration feature (PROXY protocol v2) that preserves the client's true source IP address behind an NLB, which supports accurate logging/auditing and access control based on origin IP. It is security-relevant guidance but does not address a specific vulnerability.
Evidence
+ * **PROXY protocol configuration** : this option is only available for SFTP. Turn on this option to preserve source IP addresses if your server sits behind an NLB with PROXY protocol v2 (PPv2) enabled. For more information, see [Working with Network Load Balancers](./working-with-nlb.html) and `ProxyConfig` in the [ProtocolDetails](https://docs.aws.amazon.com/transfer/latest/APIReference/API_ProtocolDetails.html) API reference.
Diff
diff --git a/transfer/latest/userguide/edit-server-config.md b/transfer/latest/userguide/edit-server-config.md index 76575c221..ec51847cf 100644 --- a//transfer/latest/userguide/edit-server-config.md +++ b//transfer/latest/userguide/edit-server-config.md @@ -74 +74,3 @@ You can change the server's properties on this page by choosing **Edit** : -Avoid placing Network Load Balancers (NLBs) or NAT gateways in front of AWS Transfer Family servers. This configuration increases costs and can cause performance issues. For more details, see [Avoid placing NLBs and NATs in front of AWS Transfer Family servers](./infrastructure-security.html#nlb-considerations) +Avoid placing Network Load Balancers (NLBs) or NAT gateways in front of AWS Transfer Family FTP and FTPS servers. This configuration increases costs and can cause performance issues. For more details, see [Avoid placing NLBs and NATs in front of AWS Transfer Family servers](./infrastructure-security.html#nlb-considerations). + + * **PROXY protocol configuration** : this option is only available for SFTP. Turn on this option to preserve source IP addresses if your server sits behind an NLB with PROXY protocol v2 (PPv2) enabled. For more information, see [Working with Network Load Balancers](./working-with-nlb.html) and `ProxyConfig` in the [ProtocolDetails](https://docs.aws.amazon.com/transfer/latest/APIReference/API_ProtocolDetails.html) API reference.