FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
kmak
Staff
Staff
Article Id 223046
Description This article describes how  to install Let’s Encrypt Certificate hosted domain in FortiWeb (Reverse Proxy Mode).
Scope FortiWeb version 7.0 and later.
Solution

Prerequisite:

- The domain to install Letsencrypt cert must be pointed and mapped to the FortiWeb's Virtual IP that going to host the domain.

- Port 80 should be publicly accessible so that Letsencrypt able to validate the domain ownership on the FortiWeb.(Refer to related document at end of article).

 

1) Add the new domain in Letsencrypt cert. Each subdomain must be created separately in order to install the Letsencrypt cert.

In this example the testing domain is 'ft-dev.site'.

 

kmak_0-1662529063941.jpeg

 

2) Create SNI and add the Letsencrypt cert into the Inline SNI.

 

kmak_1-1662529063945.jpeg

 

3) Create and add the domain HTTP Content Routing Policy.

 

kmak_2-1662529063946.jpeg

 

4) Under the 'Advanced SSL settings', check the option 'Enable Server Name Indication(SNI)' and select the created SNI policy.

 

kmak_3-1662529063948.jpeg

 

5) Make sure the 'Redirect HTTP to HTTPS' is disabled.

 

kmak_4-1662529063948.jpeg

 

6) Go back to the Letsencrypt Cert page and select the 'Issue' icon.

 

kmak_5-1662529063950.jpeg

 

7) Wait 30 seconds and the certificate status shall turn 'ok'.

 

kmak_6-1662529063951.jpeg

 

Related document:

https://docs.fortinet.com/document/fortiweb/7.0.2/administration-guide/595664/how-to-offload-or-insp...

Contributors