Hi,
i'm using VIP to redirect traffic based on hostnames to my NAS
I'm using Origin Server Certificates obtained from cloudflare that also manages my DNS.
Anyway, i'm seeing this error while trying to visit the login page:
The certificate is considered valid. Anyway in the logs i see a lot of accepted but timed out connections.
Any tips?
Hi @itcba ,
I reviewed the debug logs again. I saw a lot of "func=av_receive " line=444 msg="send to application layer" or "func=ip_session_output line=661 msg="send to ips" . That's why I asked you to review the security logs and try it without a security profile.
However, can you access port 443 of the 10.30.0.1 IP address from the internal network or via Fortigate?
Can you also try removing the http host setting under the virtual server configuration?
unset http-host "express.cba-design.it"
Yes sorry i did the try without any security profile applied but i see the same error:
I can reach the NAS from the internal network, and i can ping it from the fortigate.
How do i use the command you sent?
Hello @itcba ,
Also, can you change the ssl-inspection profile to no-inspection?
You can do the same thing without a command by removing the fqdn in this field.
Unfortunately it doesn't change anything.
The strange part is that there is no log about that! I can't find anything related to this issue!
Hi @itcba ,
Thats weird.
If you use DNS only mode instead of proxy mode in cloudflare, is there any difference?
No differences with the dns-only mode.
Hi @itcba ,
I saw you use "ssl-mode full "in your configuration. Did you install acme- express certificate on your NAS drive?
If you say no, can you install it and then try again?
if you say yes, Is Cloudflare providing you a CA certificate for acme-express? If yes, can you install this certificate to FortiGate on the System->Certificate section?
I'm not able to import it on my NAS because my synology is asking me for a private key. That certificate is obtained from LE directly from the fortigate and i'm not sure i'm able to obtain its private key
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.