Skip to main content
Hassan-wahab
Explorer
May 30, 2024
Question

Assign VIP to server in Azure Fortigate

  • May 30, 2024
  • 2 replies
  • 1118 views

Hi,

I'm using a spoke and hub topology in Azure with HA A/P Fortigate. Some of our servers need to use public IPs to communicate with external servers. I checked the documentation but couldn't find the information I need. Is it possible to assign a VIP to a server in Azure Fortigate?

 

The traffic flow is: Server > Internal LB > NVA Fortigate Firewall > External LB > Internet.

 

Thanks!

2 replies

Hong_FTNT
Staff & Editor
Staff & Editor
May 30, 2024

Hi @Hassan-wahab,

 

If the traffic is going out through the regular outbound internet connection, it should be source NATed to the public IP. Why would you need VIP? 

 

Regards, 

Hassan-wahab
Explorer
May 30, 2024

@hbacWe have up to 8 web servers that need to communicate with third parties via their unique public IPs. The client don't want us to do one to one NAT or use Azure NAT gateway. They want the inbound traffic go through our Fortigate.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!