The PingOne Protect service needs the client's public-facing (rather than local) IP address for the risk assessment. In the PingFederate administrative console, go to Security > System Integration > Incoming Proxy Settings. In the HTTP Header for Client IP Addresses field, enter X-Forwarded-For. Leave Use Last Value selected. Click Save.