aws AWS What's New ·

AWS Transfer Family adds source IP preservation for SFTP behind Network Load Balancers

securityawsgaengineer
feature

AWS Transfer Family now supports preserving the client's source IP address for SFTP servers utilizing VPC-hosted endpoints with a Network Load Balancer. This enhancement, enabled by Proxy Protocol v2, allows customers to maintain visibility of true client IPs in logs and for custom identity provider authentication. Previously, NLBs replaced client IPs, hindering IP-based auditing and access controls. The feature can be individually enabled on SFTP servers via console, CLI, or API, and is available in all AWS regions where Transfer Family operates.

Features (1)
  • Source IP preservation for SFTP servers behind Network Load Balancers

    AWS Transfer Family now preserves the client's source IP address using Proxy Protocol v2 for SFTP servers fronted by a Network Load Balancer. This enables IP-based auditing, access controls, and custom identity provider authentication, which was previously hindered by NLBs replacing client IPs. The feature is available in all AWS Regions where AWS Transfer Family is offered.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/09/transfer-family-sftp-source-ip-nlb/

Related releases