Fortinet Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NotMine
Contributor

HTTPS load balancing missing on FGT-60D

Hello everyone,

 

I'm trying to set up server load balancing on my FGT-60D, with SSL offloading. But, when I try to configure a new virtual server, I don't have an option to select HTTPS type. Here's CLI configuration process:

 

 

Is it possible that 60D does not support HTTPS load balancing?

 

Thanks!

Slavko

NSE 7

All oppinions/statements written here are my own.

1 Solution
lkorbasiewicz_FTNT

Hello,

 

Indeed, your device will not support SSL offloading. Please find more in our Feature / Platform matrix on http://docs.fortinet.com/fortigate/reference or directly for FortiOS 5.2.2 version http://docs.fortinet.com/uploaded/files/2204/fortios-feature-platform-matrix-522.pdf

 

Best Regards,

Lukasz Korbasiewicz

Lukasz Korbasiewicz,

Fortinet TAC Support

View solution in original post

3 REPLIES 3
lkorbasiewicz_FTNT

Hello,

 

Indeed, your device will not support SSL offloading. Please find more in our Feature / Platform matrix on http://docs.fortinet.com/fortigate/reference or directly for FortiOS 5.2.2 version http://docs.fortinet.com/uploaded/files/2204/fortios-feature-platform-matrix-522.pdf

 

Best Regards,

Lukasz Korbasiewicz

Lukasz Korbasiewicz,

Fortinet TAC Support

NotMine
Contributor

That's what I was afraid of. :(

 

Actually, what I really need is SSL offloading for FGT-90D, but according to this document, this model also does not support SSL offloading in version 5.2.2. Curiously enough, it is supported on FGT-90D in version 5.0.5... Why would they do this?

NSE 7

All oppinions/statements written here are my own.

emnoc
Esteemed Contributor III

it is supported on FGT-90D in version 5.0.5... Why would they do this?

 

Because SSL offloading can be  cpu/memory resource impacting and the smaller footprints do performance at best for this model and the role in question. A FGT60D is at best a entry level firewall or a  desktop SMB and that means more closer to the S in SMB

 

If you need  true SSL-offloading, than look a SLB or a bigger firewall.

 

 

PCNSE 

NSE 

StrongSwan