Why might a CDN, reverse proxy or load balancer appear instead of the original source?¶
A service may log the system immediately in front of its application rather than the connection that first arrived from the internet.
The short version¶
Fronting infrastructure changes the observation point. The application log may show a CDN, reverse proxy or load balancer, while a trusted fronting log may contain the originating connection.
A simple route¶
external connection → CDN or proxy → application
The application sees its immediate neighbour. An origin address may be carried in Forwarded, X-Forwarded-For or platform metadata, but a field name alone does not make it reliable. A client may supply a header unless the service’s trusted proxy configuration replaces or validates it.
What to ask the system owner¶
Establish which component first received the connection, which fields each layer recorded or changed, which proxies were trusted, and whether fronting and application logs share a request or session identifier. Preserve the complete event and the route configuration for the relevant date.
Do not assume the first or last address in a header chain is the user. It may be ordinary service architecture, not deliberate concealment.
The point to remember
Before using an apparent source IP, identify the layer that observed it and the trust rules that gave the value meaning.