| Description | This article describes how to resolve the '502 Bad Gateway' error accessing the website via FortiWeb-OCI server policy deployment with OCI-LB upstream. |
| Scope | FortiWeb-OCI. |
| Solution |
Topology:
Depending on the load balancer type used in OCI, usually, the LB is assigned with public IP and performs DNAT for traffic destined for FortiWeb VIP.
Typically, FortiWeb VIP is configured in backend sets configuration and the service port is HTTPS(443) parallel to FortiWeb server policy listening to service port 443(HTTPS).
Sample error while accessing the website through OCI-LB -> FortiWeb with backend set misconfiguration.
Example of FortiWeb server policy only listening to HTTPS service port 443.
Tips to verify:
Sample traffic of ‘Use SSL’ disabled in OCI backend set configuration.
Resolve the '502 Bad Gateway' error by enabling ‘Use SSL’ in OCI LB backend set configuration.
Note: Bad backend health status in OCI might also cause a ‘502 Bad Gateway’ error.
Decrypting encrypted traffic in the FortiWeb administration guide: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.