AWS Security ChangesHomeSearch

AWS transfer: Document PROXY protocol v2 source IP preservation for SFTP

Service: transfer · 2026-09-27 · Documentation medium

File: transfer/latest/userguide/infrastructure-security.md · Type: network

Summary

Adds guidance that SFTP servers can be placed behind an NLB while preserving the client's source IP address using PROXY protocol v2 (PPv2), with a link to the NLB documentation.

Security assessment

The added line documents a network security-relevant capability (PPv2) that preserves source IP addresses for SFTP servers behind an NLB, aiding logging, auditing, and IP-based controls. It is best-practice documentation rather than a fix for a specific vulnerability.

Evidence

+For servers configured with the SFTP protocol, you can place an NLB in front of the server and preserve the client's source IP address by using PROXY protocol v2 (PPv2). For more information, see [Working with Network Load Balancers](./working-with-nlb.html).

Diff

diff --git a/transfer/latest/userguide/infrastructure-security.md b/transfer/latest/userguide/infrastructure-security.md
index 5935a2a4f..5e1a331ea 100644
--- a//transfer/latest/userguide/infrastructure-security.md
+++ b//transfer/latest/userguide/infrastructure-security.md
@@ -29,0 +30,2 @@ Many customers configure a Network Load Balancer (NLB) to route traffic to their
+For servers configured with the SFTP protocol, you can place an NLB in front of the server and preserve the client's source IP address by using PROXY protocol v2 (PPv2). For more information, see [Working with Network Load Balancers](./working-with-nlb.html).
+