Created on
01-08-2024
09:35 PM
Edited on
10-05-2025
01:29 PM
By
Jean-Philippe_P
Description |
This article describes an expected behavior where the http-redirect option (configurable for Virtual Server objects) is not available when configured in NGFW policy-based mode. |
Scope | FortiGate. |
Solution |
As a primer, the http-redirect option can be configured for HTTP Virtual Server objects (aka Virtual IPs of type server-load-balance) and allows the FortiGate to redirect client requests from HTTP to encrypted HTTPS (see also: HTTP to HTTPS redirect for load balancing).
However, while this option can be utilized for FortiGates/VDOMs operating in NGFW profile-based mode, it is not available when using NGFW policy-based mode:
FortiGate # config firewall vip edit 'Test-443' set type server-load-balance edit 1 set ip 10.2.2.2 next set ip 10.3.3.3 next end next
FortiGate (vip) # edit Test-443
The reason this occurs is because the http-redirect option is a proxy-based feature (i.e., traffic is redirected the the WAD-based proxy). Since NGFW is a purely flow-based mode of operation (e.g., using the IPS Engine), it is not possible to utilize the http-redirect function, and so it is unavailable to be configured.
Several other proxy-based config options are also unavailable when using Virtual Servers in NGFW policy-mode, including http-ip-header, h3-support, h2-support, persistence, and http-multiplex. Consider using NGFW profile-based mode instead if proxy-based Virtual Server functions are required. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.