Troubleshooting Tip: WebSocket traffic fails behind HTTPS Virtual Server in Azure Active/Active deployments
Description | This article describes an issue where WebSocket‑based applications fail when published through a FortiGate HTTPS Virtual Server in an Azure Active/Active deployment. The affected environment uses an Azure External Load Balancer (ELB) in front of the FortiGates and an Azure Internal Load Balancer (ILB) behind them. Standard HTTPS traffic works normally, but WebSocket upgrade requests fail when passing through the Virtual Server. |
Scope | FortiOS. |
Solution |
Â
 These indicate that the Virtual Server is using HTTP/2 multiplexing toward the backend. Â
 To ensure WebSocket compatibility, disable HTTP multiplexing on the HTTPS Virtual Server. This forces the FortiGate to use HTTP/1.1 end‑to‑end, allowing the WebSocket upgrade handshake to pass through correctly. Â
 A related issue affecting WebSocket upgrade handling behind HTTPS Virtual Servers was resolved in:
 These versions include fixes to WAD behavior when handling WebSocket upgrade requests in environments using HTTP/2 backend multiplexing:
Upgrading to a firmware version containing the fix is recommended for long‑term stability. |
