Skip to main content
rubenc
New Member
September 7, 2015
Question

Inquiry regarding ssl offloading headers in a Fortigate

  • September 7, 2015
  • 0 replies
  • 2995 views

Hi!

 

We're purchasing 2 (for HA) FortiGate 200D units. Since our load-balancing needs are quite simple, we don't plan to acquire any separate load-balancers. The only "but" is that we require the backend servers, in some cases, to be able to know if a http request was or not https in the origin and having been ended in the ssl offloading part.

Specifically, I need to know if either X-Forwarded-Proto or(/and) Front-End-Https headers can be present in the http request sent to a backend server from the firewall, apart of (of course, and along with) the X-Forwarded-For header.

 

According to http://docs.fortinet.com/uploaded/files/800/fortigate-cli-50.pdf pages 842 and 882, both headers can be present.

 

Is this so?

 

Thanks,

 

Rubén Cardenal