# count source IP with x-forwarded-for

**URL:** <https://community.a10networks.com/t/count-source-ip-with-x-forwarded-for/389>\
**Category:** aFleX\
**Created:** [May 11, 2016, 4:09am UTC](https://community.a10networks.com/t/count-source-ip-with-x-forwarded-for/389 "2016-05-11T04:09:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chen](https://avatars.discourse-cdn.com/v4/letter/c/3d9bf3/32.png) [@chen](https://community.a10networks.com/u/chen)\
**Post date:** [May 11, 2016, 4:09am UTC](https://community.a10networks.com/t/count-source-ip-with-x-forwarded-for/389/1 "2016-05-11T04:09:53Z")

</div>

Hi  
May I count source IP with x-forwarded-for filed by aflex? ex: if one the same source IP connection more then 1000 in one min or 5 min, then log in syslog.

I have referred “rate-limit-connection-requests” tcl, like below:

when RULE\_INIT { set ::MAX\_REQUESTS 1000 } when HTTP\_REQUEST { if { [HTTP::header exists “X-Forwarded-For”] } { set IP [getfield [HTTP::header X-Forwarded-For] “,” 1] } else { set IP [IP::client\_addr] } if { [table lookup tmp\_request $IP] == “” } { table set tmp\_request $IP 1 log “$IP → request counter created” } set request\_count [table incr tmp\_request $IP] if { $request\_count \> $::MAX\_REQUESTS } { log "$IP connection \> $::MAX\_REQUESTS " } }

But it seem accumulator IP in the table,can’t count by timers(sec or min) Does there have solution for this ? Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex002/uploads/a10_community/original/1X/bb9f186d33804d3044a0374e589f49fdf3be1328.png) [@system](https://community.a10networks.com/u/system)\
**Post date:** [May 11, 2016, 9:58pm UTC](https://community.a10networks.com/t/count-source-ip-with-x-forwarded-for/389/2 "2016-05-11T21:58:35Z")

</div>

`Hi Chen,

Hope this works for you.

when RULE\_INIT { set ::MAX\_REQUESTS 100 # timelimit in seconds set ::TIMELIMIT 60 }

when HTTP\_REQUEST { if { [HTTP::header exists “X-Forwarded-For”] } { set IP [getfield [HTTP::header X-Forwarded-For] “,” 1] } else { set IP [IP::client\_addr] } # Check if there is an entry for the client\_addr in the table if { [table lookup tmp\_table -notouch $IP] != “” } { # If the value is less than MAX\_REQUESTS (1000) increment it by one if { [table lookup tmp\_table -notouch $IP] \< $::MAX\_REQUESTS } { log “Number of requests from client = [table lookup tmp\_table -notouch $IP]” table incr tmp\_table -notouch $IP 1 } else { # log the message with the ratelimit exceeds log “Client has exceeded the number of allowed requests of [table lookup tmp\_table -notouch $IP]” } } else { # If there is no entry for the client\_addr create a new table to track number of HTTP\_REQUEST. timeout is set to TIMELIMIT mentioned log " Table created for $IP " table set tmp\_table $IP 1 $::TIMELIMIT } }

#the table with client IP, timeout will be the TIMELIMIT mentioned.

---

<div class="post-metadata">

**Author:** ![chen](https://avatars.discourse-cdn.com/v4/letter/c/3d9bf3/32.png) [@chen](https://community.a10networks.com/u/chen)\
**Post date:** [May 12, 2016, 5:38am UTC](https://community.a10networks.com/t/count-source-ip-with-x-forwarded-for/389/3 "2016-05-12T05:38:05Z")

</div>

Hi Avinash,  
Thank you very much , this helpful for me.  
Thank you again .

---

<div class="post-metadata">

**Author:** ![chen](https://avatars.discourse-cdn.com/v4/letter/c/3d9bf3/32.png) [@chen](https://community.a10networks.com/u/chen)\
**Post date:** [May 13, 2016, 3:01am UTC](https://community.a10networks.com/t/count-source-ip-with-x-forwarded-for/389/4 "2016-05-13T03:01:59Z")

</div>

Hi,  
I get error message "aFleX syntax error: line 9: “unknown command “table”” when apply the aflex to AX serial ( it is work on ACOS serial ) , does AX serial not support “table” syntax?  
Thanks for your support.
