Hi all,
We are looking into the Forigate 300D as a replacement for our internal TMG.
We know that the 300D can cover most of the functionality we need, but we are unsure if it can cover the reverse proxy requirements.
We publish Exchange and ADFS through TMG, is there a way we can publish these service with the Fortigate instead?
Thank you
Sean
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
It can be done! Use (Server) "Load Balance" feature, with one real server to "balance".
Dimitris
Hello,
Yes, Fortigate does it, but depends on the configuration.
If it is a generic VIP, only the Destination NAT happens, if it involves SSL inspection or load balancing(in Virtual Server), it does reverse proxy.
Hi,
How can we check if the reverse proxy is done ?
I configured my VIP like that :
config firewall vip
edit "www" set type server-load-balance set extip x.x.x.x set extintf "wan1" set server-type http set extport 80 config realservers edit 1 set ip 10.9.0.13 set port 80 next end nextend
config firewall policy edit 11 set srcintf "WAN" set dstintf "LAN" set srcaddr "all" set dstaddr "www" "vdoc" set action accept set schedule "always" set service "HTTP" set utm-status enable set av-profile "AV_SRV" set ips-sensor "IPSServer" set profile-protocol-options "ReverseProxy" set ssl-ssh-profile "certificate-inspection" next end config antivirus profile edit "AV_SRV" set inspection-mode proxy config http set options scan end next end config firewall profile-protocol-options edit "ReverseProxy" config http set ports 80 set options clientcomfort set comfort-amount 5 unset post-lang end next end
Thanks !
Lucas
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.