Assistance Required for FortiWeb in (Reverse Proxy)
Hello Fortinet Community,
We are in the process of configuring FortiWeb 7.4.3 as a reverse proxy for our on-premises web servers. Our FortiWeb deployment is VM-based. Alongside hosting a web service, these servers are also involved in IP-Sec tunnels established on our core firewall (FortiGate) with various financial institutions.
Our objective is to bypass traffic destined for these IP-Sec tunnels through FortiWeb, excluding HTTPS/HTTP traffic directed towards the web servers (HTTP/HTTPS Traffic should be inspected in FortiWeb)
We seek clarification on the following points:
IP-Sec Tunnel Bypass: How can we ensure that traffic intended for the IP-Sec tunnels bypasses FortiWeb? Are there specific configurations or policies within FortiWeb that we should implement to achieve this seamlessly?
Impact on Financial Institutes' Settings: Will configuring our servers behind the WAF (Web Application Firewall) necessitate any changes at the end of the financial institutes regarding their IP-Sec tunnel settings? Are there any considerations such as altering IP addresses or other parameters that we should communicate to them?
Downtime Considerations: Lastly, we need to ascertain if implementing these changes will require any downtime for our services or disruptions to the established IP-Sec tunnels.
We appreciate any insights, best practices, or guidance from the community or Fortinet experts regarding the above queries.
#FortiWeb #WAF #Fortinet
