This request reached the origin directly, with no zero trust edge and no authenticated identity. Any client able to route to this load balancer can retrieve this page.
Access path
Direct to origin
Zero trust vendor
none detected
Device agent
no
Application identity
Not enabled
Assessment
Application
ZTNA Public App
Exposure
public
Access path
Direct to origin
Zero trust vendor
none
Device agent detected
no
Edge identity
ALB OIDC not enabled at this ALB
Basis for classification
no ZTNA edge signals in the request
Client and forwarding chain
Effective client address
216.73.216.182
Claimed client (leftmost)
216.73.216.182
Load balancer peer (rightmost)
216.73.216.182
Full X-Forwarded-For chain
216.73.216.182
Cf-Connecting-IP
absent
X-Forwarded-For is processed in append mode, so the rightmost entry is the host that opened the connection to the load balancer and the leftmost is the originally claimed client. On a direct request the leftmost value is supplied by the caller and must not be treated as trustworthy.
Cloudflare
cf-access-jwt-assertion
absent
cf-access-authenticated-user-email
absent
cf-access-client-id
absent
cf-warp-tag-id
absent
cf-connecting-ip
absent
cf-ray
absent
cf-ipcountry
absent
cf-visitor
absent
cf-worker
absent
cdn-loop
absent
Edge location (from Cf-Ray)
absent
Issuer matches configured team
not determined
Configured team domain
not determined
Cf-Access-Jwt-Assertion
Header absent.
Palo Alto / Prisma Access
Configured Prisma egress ranges
none
Peer within Prisma egress range
no
Prisma Access Browser (User-Agent hint)
no
GlobalProtect HIP device posture is evaluated in the firewall and is never injected into HTTP. This application cannot observe it. The app-visible Prisma evidence is source IP, User-Agent, and any headers Prisma Access Browser is configured to inject.
Transport
host
ztna-public.hacks.dev.cloud.huit.harvard.edu
x-forwarded-for
216.73.216.182:48871
x-forwarded-proto
https
x-forwarded-port
443
x-amzn-trace-id
Root=1-6a8e1891-27eb1b2148beb77d0268d36b
x-amzn-tls-version
TLSv1.3
x-amzn-tls-cipher-suite
TLS_AES_128_GCM_SHA256
user-agent
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
sec-ch-ua
absent
sec-ch-ua-platform
absent
sec-ch-ua-mobile
absent
accept-language
absent
referer
absent
Session cookies present
none
Load balancer OIDC (HarvardKey)
OIDC pre-authentication is not enabled on this load balancer. The zero trust baseline is measured first, without a second identity layer, so that an access failure has a single candidate explanation. Set enable_oidc = true in the environment configuration to add the HarvardKey layer.