I'd like to create the following setup:

When the site is accessed by the internal LAN there's not need for
When the site is accessed from outside (Internet) there should be and
authentication procedure.

So I configured an authentication policy with Client IP, but I cannot
get this working.
I checked the catalina.out on the AG and shows me that the policy sees
as ClientIP, the IP address from the L4 switch (Cisco ACE).

Is there way the get here the real client IP on the AG?

Version: 4.1

