Skip to main content
mtousignant
New Member
February 26, 2016
Question

How to deal with non-https/http traffic?

  • February 26, 2016
  • 1 reply
  • 3387 views

Whats the best way to handle non-https/http traffic?

 

This is a web server, that also offers some other services. Currently. 

 

Gate(VIP pointing to web server) -> MPLS -> GATE -> web server

 

Atm, I almost feel like I am going to have to split the VIP on our outer gate into two IPs, one for the HTTP (pointing to the fortiweb) and the other bypassing the fortiweb containing the other service.

 

Gate(HTTP VIP) -> MPLS -> Gate -> Fortiweb(reverse proxy) -> Web server

Gate(SERVICE VIP) -> MPLS -> Gate -> Web server

 

Is there a better way to handle this? This feels flawed to me. 

    1 reply

    abelio
    SuperUser
    SuperUser
    February 27, 2016

    mtousignant wrote:

     

    Is there a better way to handle this? This feels flawed to me. 

    Hi, What is the problem with that?

    A WAF is  for proxying HTTP/HTTPS traffic; it has nothing to do with another services/protocol.

     

    Do you concern about how could manage your FortiMail,  sql or another non-email traffic for instance?

     

    regards,