Received X-Forwarded-For header from an untrusted proxy 172.30.33.6

Hi. I am using Cloudflare Tunnel (“cloudflared”) and receiver error: Received X-Forwarded-For header from an untrusted proxy 172.30.33.6. I added all current IP ranges from the Cloudflare IP-List as trusted proxies. 172.30.33.6 is none of it, but I no it is a legitimate request from one of my smartphones over the configured domain.

Are there more IPs to configure?

That is a private LAN IP.

NetRange:       172.16.0.0 - 172.31.255.255
CIDR:           172.16.0.0/12
NetName:        PRIVATE-ADDRESS-BBLK-RFC1918-IANA-RESERVED
NetHandle:      NET-172-16-0-0-1
Parent:         NET172 (NET-172-0-0-0-0)
NetType:        IANA Special Use
OriginAS:
Organization:   Internet Assigned Numbers Authority (IANA)
RegDate:        1994-03-15
Updated:        2013-08-30
Comment:        These addresses are in use by many millions of independently operated networks, which might be as small as a single computer connected to a home gateway, and are automatically configured in hundreds of millions of devices.  They are only intended for use within a private context  and traffic that needs to cross the Internet will need to use a different, unique address.
Comment:
Comment:        These addresses can be used by anyone without any need to coordinate with IANA or an Internet registry.  The traffic from these addresses does not come from ICANN or IANA.  We are not the source of activity you may see on logs or in e-mail records.  Please refer to http://www.iana.org/abuse/answers
Comment:
Comment:        These addresses were assigned by the IETF, the organization that develops Internet protocols, in the Best Current Practice document, RFC 1918 which can be found at:
Comment:        http://datatracker.ietf.org/doc/rfc1918
Ref:            https://rdap.arin.net/registry/ip/172.16.0.0
1 Like

My fault. I am using Cloudflared within Zero Trust and that requires to add a private network IP range as trusted proxies.

Thank you for that hint!

1 Like

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.