Created on 05-28-2024 07:33 AM Edited on 08-23-2024 12:01 AM By Jean-Philippe_P
Description | This article explains how to configure a virtual server on a FortiGate running in multi-VDOM mode so that the servers reside behind VDOMs that do not have internet access. |
Scope | FortiGate. |
Solution |
This load-balancing setup utilizes several features:
Note: This configuration assumes the Internet connection is present only on the ‘EXT-VDOM’ and the web servers are placed behind the ‘INT-VDOM’ on the FortiGate.
Configuration On EXT-VDOM:
Virtual Server Configuration on EXT-VDOM.
The virtual server is configured with a load-balancing method of Round Robin.
Configure a Static Route to the Virtual Server:
The static route is configured as the destination is set to the subnet of the servers and the gateway is set to the internal interface connecting the VDOMs (inter-VDOM link).
Firewall Policy Configuration:
For the virtual server to be included in the firewall policy, the inspection mode needs to be set to 'Proxy-based'.
Configuration On INT-VDOM.
Static Route config:
Configuration of firewall policy:
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.