1. install mod_remoteip && `RemoteIPHeader X-Forwarded-For` 1. install 3.0 apache connector 1. do a hit w/ X-Forwarded-For: 1.2.3.4 1. 1.2.3.4 is not what is in the audit log 1. try again w/ mod_security2 1. 1.2.3.4 is what is in the audit log Our friends at immunify 360 who noticed this may have more detailed reproduction steps or other info to add. Note: at this time we have not tried to see is the NGINX connector behaves the same or not.