Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fortihills
New Contributor

Can't Add Virtual Server as Destination In Policy

Hi

 

I'm trying to set up SSL offloading, but I can't see the Virtual server in the list of address to assign to the destination in the policy.

What am I doing wrong? I don't have central NAT enabled.

1 Solution
ben_schaefer
New Contributor

This one just got me too.... Make sure that the Firewall Policy's Inspection Mode is set to "Proxy-based", the Virtual Servers will not appear in the list if it is in "Flow-based"

View solution in original post

5 REPLIES 5
mauromosc
New Contributor

Hi, Fortihills,

 

What is the version for your FortiGate?

 

Are you trying to configure a Policy to allow the traffic to your servers using VIP or are you trying to configure the SSL offloading?

 

Regards,

Mauro.

emnoc
Esteemed Contributor III

Are you doing full or half. You have the vip define go into the policy and add the vip as a dstaddr and show or tell us what error you get .

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
fortihills

v6.4.2 build1723 It's a new AWS VM, otherwise I'd be running 6.0.10. We ran into trouble trying to downgrade.

 

I'm trying to create a policy to allow the traffic. My understanding is I should add the virtual server that's doing the offloading as the destination address in the policy, but I don't see the virtual server in the list of available destination addresses.

mauromosc

Hi, Fortihills,

 

This sounds silly, but do you have the VIP configured? Also are you configuring this Policy under Policy & Objects > IPv4 Policy? 

 

If possible, take a screenshot from the screen to we see what is the situation.

 

Thanks and regards,

Mauro.

ben_schaefer
New Contributor

This one just got me too.... Make sure that the Firewall Policy's Inspection Mode is set to "Proxy-based", the Virtual Servers will not appear in the list if it is in "Flow-based"

Labels
Top Kudoed Authors