Skip to main content
darisandy
Staff
Staff
January 15, 2025

Technical Tip: Web Filter Profile for incoming a Virtual IP connection

  • January 15, 2025
  • 0 replies
  • 1108 views
Description This article describes how to configure a Web Filter profile for incoming connection to a Virtual IP object
Scope FortiGate.
Solution

Most of the time, a Web Filter profile is used to restrict outgoing connection from internal users to the Internet but there may be scenarios where users need to restrict incoming connection to the company's published web server.

 

Example scenario:

Client - Internet - Edge FortiGate - Web Server

 

The Edge FortiGate will have Virtual IP configured to translate incoming connection to an internal web server. The internal web server will use a different FortiGate Web GUI for the simulation.

 

The end user will restrict incoming connections using only using Fully Qualified Domain Name (FQDN), and it will block any other access, for example using the resolved public IP address.

 

Virtual IP Configuration:

 

VIP05.png

 

Web Filter Profile setting:

 

VIP04.png

 

Firewall Policy configuration:

 

VIP06.png

 

Once these are all configured, the result will be like below.

 

When using FQDN:

 

VIP01.png

 

 

When using a public IP Address:

 

VIP02.png

 

Web Filter profile for incoming connection to a virtual server also works when the virtual server 'server-type' is https. If the  virtual server 'server-type' is SSL, the Web Filter profile does not work.  

 

config firewall vip

    edit "test-server"

        set type server-load-balance

        set server-type https             

    next

end

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!