Apply x-forwarded-for to source clients too.
Apply x-forwarded-for first (before break).
use modern SSL setup