Skip to content
Skip to main content
IP Addresses & Networks Technical Explainer

Why might a CDN, reverse proxy or load balancer appear instead of the original source?

A service may log the system immediately in front of its application rather than the connection that first arrived from the internet.

The short version

Fronting infrastructure changes the observation point. The application log may show a CDN, reverse proxy or load balancer, while a trusted fronting log may contain the originating connection.

A simple route

external connection → CDN or proxy → application

The application sees its immediate neighbour. An origin address may be carried in Forwarded, X-Forwarded-For or platform metadata, but a field name alone does not make it reliable. A client may supply a header unless the service’s trusted proxy configuration replaces or validates it.

What to ask the system owner

Establish which component first received the connection, which fields each layer recorded or changed, which proxies were trusted, and whether fronting and application logs share a request or session identifier. Preserve the complete event and the route configuration for the relevant date.

Do not assume the first or last address in a header chain is the user. It may be ordinary service architecture, not deliberate concealment.

The point to remember

Before using an apparent source IP, identify the layer that observed it and the trust rules that gave the value meaning.

Reference: IP-104IP Addresses & Networks