Description | This article describes how to configure Proxy policy while using a web proxy forwarding server. |
Scope | FortiGate. |
Solution |
In a proxy setup the Forwarding-server configuration is as below:
config web-proxy forward-server
And this forward-server is reachable via port3:
Routing table for VRF=0
However, the Proxy policy should be configured as per the default route on the Fortigate but not the outgoing interface set to port3 as the policy will not take a hit.
Correct Proxy policy for the above scenario:
config firewall proxy-policy
Use following command to verify the health of the forward-server.
diag sys health-check show
Note 1: Both the explicit proxy device and the forward server should be able to resolve the hostnames for the requests coming from the client.
Note 2: In FortiOS 7.6.3 isolator servers can be configured for explicit and transparent proxy policies in the GUI of the FortiGate. Web proxy isolator servers, such as FortiIsolator, are supported in proxy policies. Isolators are fundamentally the same as web proxy forward servers because both will redirect HTTP and HTTPS requests to an HTTP or HTTPS proxy server. However, isolators have the specific function of isolating potentially unsafe traffic from a user environment. For more information refer to this document. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.