AWS Transfer Family now supports source IP preservation for SFTP servers behind a Network Load Balancer (NLB)

AWS Transfer Family Source IP Preservation
AWS Transfer Family now preserves the client's source IP address using Proxy Protocol v2 (PPv2) when you place a Network Load Balancer (NLB) in front of your SFTP server that uses a VPC-hosted endpoint. This feature allows you to retain visibility of the client's source IP for IP-based auditing, access controls, and compliance when you use your own NLB.
Previously, an NLB replaced the client's source IP with its own private IP address, which was recorded in your logs and events. With this update, the client's source IP is preserved and presented to your custom identity provider during authentication.
What to do
- Enable source IP preservation on your SFTP server through the console, CLI, or API.
- Check the availability of this feature in all AWS Regions where AWS Transfer Family is available.
- Visit the AWS Transfer Family console or use the AWS CLI/SDK to get started.
- Refer to the Transfer Family User Guide for more information.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



