Skip to main content
Christian_89
Contributor III
May 29, 2022
Question

FortiWEB Problem https

  • May 29, 2022
  • 3 replies
  • 3793 views

Hello everyone

I have the following problem with a customer.
The customer customer has an Exchange on-Perm.
For OWA access, this runs through the FortiWEB VM.
Now the problem is that this connection does not work again and again. When I check the FortiWeb I always get Connection Timeout from the Exchange.
But if I do the whole thing with the Fortigate, it works without any problems.
If I change the confg. Exhibit and readjust with us It works perfectly.

Does anyone have any tips or ideas as to what could be the issue.

Thank you very much for your help

Greeting

Christian

3 replies

AEK
SuperUser
SuperUser
May 29, 2022

Hi Christian

 

The issue can have many reasons.

 

First of all you should check traffic logs on FWB, FGT & web server to see if traffic is denied or missing somewhere.

 

Then try detect if the issue is in the front-end or in the back-end to reduce troubleshooting surface.

- ping & tracert from your PC to your FWB VS

- ping from FWB to back-end web server port 80/443

- telnet from your PC to your FWB

- telnet from your FWB to your back-end server port 80/443

 

You can also use packet sniffers to check if any traffic.

- Use tcpdump or wireshark on the web server to check if any traffic is coming from FWB

- Use diag sniffer on FGT & FWB to check if the sent packets get any response from the other side

 

Also you can try download & install a new FWB VM from scratch. Verify the checksum before installation.

 

AEK
jintrah_FTNT
Staff
Staff
May 30, 2022

Hi,

 

We should check why there is a connection timeout from FortiWeb to Exchange. Is the exchange gateway not pointing towards FortiWeb? If not, the traffic from FortiWeb should be NATed with FortiWeb interface IP address so that Exhange servers can send the traffic back to it.

 

Best regards,

Jin

Christian_89
Contributor III
May 30, 2022

Hi Jin

No, the gateway is from the Fortigate.

jintrah_FTNT
Staff
Staff
May 30, 2022

Ok about the gateway of exchange. So the return traffic from Exchange is trying to go out to internet directly from FortiGate? Or is Source NAT enabled on FortiWeb so that return traffic from exchange reaches FortiWeb? This should be checked as you had connection timeouts.

 

Best regards,

Jin

Christian_89
Contributor III
June 16, 2022

I tried the whole thing with a new address. I have no problems with this one.
Would you suggest if I reinsert the original address to make everything new?

jintrah_FTNT
Staff
Staff
June 16, 2022

Hi,

Before reinserting the original address, make sure it is not used or defined anywhere in the setup or in any configurations. Otherwise, it should just work like the new address.

 

Best regards,

Jin