Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Daniyal007
New Contributor II

Allowing Internet Traffic for backend servers in fortiweb

Hi there,

My query is regarding Forti web,

i have servers connected to the back of Forti web in reverse proxy mode but my backend server needs to connect to its update portal outside but can not connect.

is there any outgoing policy or any way to allow my specific server for allowing internet for updates.

Thanks

1 Solution
AEK

Hello

Tested successfully and there was no downtime.

AEK

View solution in original post

AEK
11 REPLIES 11
AEK
SuperUser
SuperUser

Hi @Daniyal007 

As you know ForiWeb is WAF/reverse proxy. Your server doesn't need to reach internet through FortiWeb. If the default GW for your server is the firewall then just add a firewall rule in you firewall to allow your server access the public update repositories.

 

AEK
AEK
Daniyal007
New Contributor II

i have set my server in one ARM mode means that server gateway is set on fortiweb Screenshot 2024-05-07 193026.png

Yurisk
SuperUser
SuperUser

Have a look here https://community.fortinet.com/t5/FortiWeb/Technical-Tip-Provide-Internet-access-to-a-server-behind-... 

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
Daniyal007
New Contributor II

Does enabling Ip Forwarding feature requires down time because backend servers are in production.

 

AEK

Enabling the feature doesn't require downtime. But changing the config may do.

AEK
AEK
Daniyal007
New Contributor II

ok so i have to enable ip forwarding enable and then i have to configure SNAT. 

Does configuring SNAT my cause downtime ? because im not changing the server policy nor configuring anything except SNAT in firewall . 

AEK

In theory it shouldn't impact since this is SNAT (for outbound traffic), which is different than the reverse proxy function. But let me double-check this before you do.

AEK
AEK
Daniyal007
New Contributor II

ok i am waiting for your confirmation

AEK

Hello

Tested successfully and there was no downtime.

AEK
AEK
Labels
Top Kudoed Authors