ZTNA Public App

Zero trust access evidence

public

No zero trust controls detected

This request reached the origin directly, with no zero trust edge and no authenticated identity. Any client able to route to this load balancer can retrieve this page.

Access path
Direct to origin
Zero trust vendor
none detected
Device agent
no
Application identity
Not enabled

Assessment

ApplicationZTNA Public App
Exposurepublic
Access pathDirect to origin
Zero trust vendornone
Device agent detectedno
Edge identityALB OIDC not enabled at this ALB
Basis for classificationno ZTNA edge signals in the request

Client and forwarding chain

Effective client address216.73.216.182
Claimed client (leftmost)216.73.216.182
Load balancer peer (rightmost)216.73.216.182
Full X-Forwarded-For chain216.73.216.182
Cf-Connecting-IPabsent
X-Forwarded-For is processed in append mode, so the rightmost entry is the host that opened the connection to the load balancer and the leftmost is the originally claimed client. On a direct request the leftmost value is supplied by the caller and must not be treated as trustworthy.

Cloudflare

cf-access-jwt-assertionabsent
cf-access-authenticated-user-emailabsent
cf-access-client-idabsent
cf-warp-tag-idabsent
cf-connecting-ipabsent
cf-rayabsent
cf-ipcountryabsent
cf-visitorabsent
cf-workerabsent
cdn-loopabsent
Edge location (from Cf-Ray)absent
Issuer matches configured teamnot determined
Configured team domainnot determined

Cf-Access-Jwt-Assertion

Header absent.

Palo Alto / Prisma Access

Configured Prisma egress rangesnone
Peer within Prisma egress rangeno
Prisma Access Browser (User-Agent hint)no
GlobalProtect HIP device posture is evaluated in the firewall and is never injected into HTTP. This application cannot observe it. The app-visible Prisma evidence is source IP, User-Agent, and any headers Prisma Access Browser is configured to inject.

Transport

hostztna-public.hacks.dev.cloud.huit.harvard.edu
x-forwarded-for216.73.216.182:48871
x-forwarded-protohttps
x-forwarded-port443
x-amzn-trace-idRoot=1-6a8e1891-27eb1b2148beb77d0268d36b
x-amzn-tls-versionTLSv1.3
x-amzn-tls-cipher-suiteTLS_AES_128_GCM_SHA256
user-agentMozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
sec-ch-uaabsent
sec-ch-ua-platformabsent
sec-ch-ua-mobileabsent
accept-languageabsent
refererabsent
Session cookies presentnone

Load balancer OIDC (HarvardKey)

OIDC pre-authentication is not enabled on this load balancer. The zero trust baseline is measured first, without a second identity layer, so that an access failure has a single candidate explanation. Set enable_oidc = true in the environment configuration to add the HarvardKey layer.

Request headers

Show all 10 forwarded headers
{
  "accept": "*/*",
  "accept-encoding": "gzip, br, zstd, deflate",
  "host": "ztna-public.hacks.dev.cloud.huit.harvard.edu",
  "user-agent": "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)",
  "x-amzn-tls-cipher-suite": "TLS_AES_128_GCM_SHA256",
  "x-amzn-tls-version": "TLSv1.3",
  "x-amzn-trace-id": "Root=1-6a8e1891-27eb1b2148beb77d0268d36b",
  "x-forwarded-for": "216.73.216.182:48871",
  "x-forwarded-port": "443",
  "x-forwarded-proto": "https"
}