Skip to main content
AlexFeren
New Member
February 9, 2018
Question

Port-pair (virtual wire) and Explicit Proxy

  • February 9, 2018
  • 0 replies
  • 1619 views

We have Explicit Proxy configured on our 1500D, v5.2.6, in Transparent Mode VDOM.

 

I understand that even in Transparent Mode, Explicit Proxy traffic is routed, however, Port pairing in Transparent mode documentation is very clear - "all traffic accepted by one of the paired interfaces can only exit out the other interface."

 

However, when second interface of the port-pair was (unintentionally) physically disconnected, the Explicit Proxy still worked through the one interface, as the (default) gateway was accessible on the same interface as Explicit Proxy clients, effectively making "on-a-stick" implementation.

 

My question - the current implementation seems to contradict the referenced Fortinet documentation - is that an anomaly or intentional (for Explicit Proxy case)?

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!