I ask the TAC like this @ the case number 5390248464
"
Could you please get back to me on this quick:
- Does the CPPM need to know the client's IP address?
Because F5 is acting as full-proxy, and sometimes in their design, it will do Source-NAT. So, if the F5 does Source-NAT, and F5 maintains the Source IP in a X-Forwarded-For packet, can the CPPM read the X-Forwarded-For packet and see the original client IP even though F5 does the Source-NAT?
Let me know if you need further clarification.
"
Is there any documents stating CPPM able to read XFF ?
Original Message:
Sent: Jun 12, 2025 02:22 PM
From: eduardomozart_rnetworks
Subject: ClearPass Guest Portal behind Reverse Proxy
Yes, I was able to reverse proxy ClearPass WebUI (including Administration and Guest Portal) behind Fortigate Virtual Server and pfSense HAProxy. It's possible and works as expected, which makes easier to use Let's Encrypt certificates through ClearPass. Other possibility is using a third party script to upload a Let's Encrypt certificate automatically to ClearPass before it expires if you have difficulties in making it to work.
Original Message:
Sent: Jun 06, 2025 03:17 AM
From: breenubee
Subject: ClearPass Guest Portal behind Reverse Proxy
Hi All,
Is this feature now available? Any release notes for this? We have F5 in our deployment and we are about to load-balance the OnGuard HTTPS and TCP 6658 traffic, and about to discuss it with F5 principal. TAC Case opened for this: 5390248464.
Main topic to discuss is whether we should go for one-arm F5 design or two-arm (which I do not really understand), and whether ClearPass needs to return back the TCP traffic through F5 and does not let asymmetric routing to happen. I am not so experienced in networking, so I would like some help from anyone here.
Cheers. Thanks beforehand.
Original Message:
Sent: Jan 24, 2019 05:05 PM
From: ricardoduarte
Subject: ClearPass Guest Portal behind Reverse Proxy
I see.
So, I followed your advice and created an "Idea" for this.
Thanks.