AWS transfer: Document PROXY protocol v2 source IP preservation for SFTP
Summary
Adds guidance that SFTP servers can be placed behind an NLB while preserving the client's source IP address using PROXY protocol v2 (PPv2), with a link to the NLB documentation.
Security assessment
The added line documents a network security-relevant capability (PPv2) that preserves source IP addresses for SFTP servers behind an NLB, aiding logging, auditing, and IP-based controls. It is best-practice documentation rather than a fix for a specific vulnerability.
Evidence
+For servers configured with the SFTP protocol, you can place an NLB in front of the server and preserve the client's source IP address by using PROXY protocol v2 (PPv2). For more information, see [Working with Network Load Balancers](./working-with-nlb.html).
Diff
diff --git a/transfer/latest/userguide/infrastructure-security.md b/transfer/latest/userguide/infrastructure-security.md index 5935a2a4f..5e1a331ea 100644 --- a//transfer/latest/userguide/infrastructure-security.md +++ b//transfer/latest/userguide/infrastructure-security.md @@ -29,0 +30,2 @@ Many customers configure a Network Load Balancer (NLB) to route traffic to their +For servers configured with the SFTP protocol, you can place an NLB in front of the server and preserve the client's source IP address by using PROXY protocol v2 (PPv2). For more information, see [Working with Network Load Balancers](./working-with-nlb.html). +