Skip to main content
Daniyal007
Explorer
May 10, 2024
Question

IP sec tunnel connection from fortiweb

  • May 10, 2024
  • 3 replies
  • 2023 views

Hi there,

I have fortigate configured as my EDGE device and some ip sec tunnel are created in that fortigate device to access servers behind firewall.

now we have put fortiweb between server and fortigate. everything is working fine but i want to know that how ipsec tunnel created on fortigate can communicate to the server which is back at fortiweb 

need some help please.

Thanks

3 replies

AEK
SuperUser
SuperUser
May 10, 2024

Hi Dan

Suppose your FWB's VIP is in DMZ. Create a firewall policy like this:

  • srcintf: IPsec tunnel interface
  • dstintf: DMZ
  • from: IPsec tunnel IP range
  • to: FWB-VIP
  • service: HTTP, HTTPS

And you are done.

AEK
Daniyal007
Explorer
May 10, 2024

the traffic of ipsec is SFTP and i want to that does we have to do any changes remote site?

AEK
SuperUser
SuperUser
May 10, 2024

I think a similar post has just been resolved.

https://community.fortinet.com/t5/Support-Forum/Assistance-Required-for-FortiWeb-in-Reverse-Proxy/m-p/314240

Hope it helps. Otherwise please elaborate a bit more so we can help.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!