Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
youmustbecrazy
New Contributor II

Accessing FortiProxy Explicit Proxy from Internet via NAT

Hi All,

 

My boss has asked to me is it possible to accessing proxy server via public IP or FQDN which published to public?
The goals is he want to use proxy from internet while out of office.
I have suggest to use PAC for another option but he asked for first option possibility.

 

Can you guys help me for the solution like this is possible or do you have alternate solution to achieve the goals?

FortiProxy FortiGate 


Screenshot 2024-06-19 105434.png

1 Solution
Sx11
Staff
Staff

Hello youmustbecrazy, :)

 

So the use case is to provide secure user access to remote users connecting from anywhere.

Your suggestion should work in this case even though it might not be the best user experience for remote users. Traffic in this case will be redirected internally to your FGT, then FPX for inspection and to internet.

 

However i would suggest a more elegant and simpler solution by using SASE SIA with secure web gateway (SWG) functionality. This is an agentless solution that uses same Explicit web proxy feature of FortiOS but as a cloud instance.

 

It will provide following benefits:

- Simpler administration and configuration.

- Remove the extra load of Remote user traffic inspection from the on-premise Instrastructure.

- Scalable solution in case number of Remote user increases in the future.

 

You can check this guide for reference showing how this works:

https://docs.fortinet.com/document/fortisase/latest/architecture-guide/834810/sia-for-agentless-remo...

 

SASE SIA demo from fortinet video library:

https://video.fortinet.com/latest/fortisase-sia-demo

 

Regards

sx11

View solution in original post

2 REPLIES 2
Sx11
Staff
Staff

Hello youmustbecrazy, :)

 

So the use case is to provide secure user access to remote users connecting from anywhere.

Your suggestion should work in this case even though it might not be the best user experience for remote users. Traffic in this case will be redirected internally to your FGT, then FPX for inspection and to internet.

 

However i would suggest a more elegant and simpler solution by using SASE SIA with secure web gateway (SWG) functionality. This is an agentless solution that uses same Explicit web proxy feature of FortiOS but as a cloud instance.

 

It will provide following benefits:

- Simpler administration and configuration.

- Remove the extra load of Remote user traffic inspection from the on-premise Instrastructure.

- Scalable solution in case number of Remote user increases in the future.

 

You can check this guide for reference showing how this works:

https://docs.fortinet.com/document/fortisase/latest/architecture-guide/834810/sia-for-agentless-remo...

 

SASE SIA demo from fortinet video library:

https://video.fortinet.com/latest/fortisase-sia-demo

 

Regards

sx11
youmustbecrazy
New Contributor II

Hi @Sx11 thank you very much for your advice. The proxy can be able using public IP via NAT, and it works perfectly!.
maybe I will tell my boss to consider using SASE, need to review it first.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors