Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
markbo
New Contributor

FortiGate Proxy 2-staged setup

Hi,

 

am I correct that in an 2-staged Firewall setup with one Edge and one internal Firewall Cluster (and an DMZ between Thema) , I have to Put the explicit Proxy configuration in the Edge Firewall, because there I can setup Security profiles such Like webfiltering and so on? I am a Bit curious about the Interface configuration of the Edge Firewall for the explicit Proxy. 

 

Mark

2 REPLIES 2
Anonymous
Not applicable

Hello @markbo ,
 
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
 
Thanks,
lol
Staff
Staff

Hello,

 

The explicit proxy does not have to run on the perimeter / edge firewall.

It can also run on the internal firewall.

 

But it is likely easier to achieve when setup on the external device.

 

You just need to make sure the device on which the proxy runs has access to the internet.

Mandatory is a working DNS resolution.

For any kind of TLS inspection the device must be able to fetch the certificate trust chain, CRLs, query OCSP servers, query the destination servers to verify the certificate, etc.

For web or DNS filtering the Fortiguard servers must be reachable.

The same for any kind of signature based scanning to download current signature updates from Fortiguard.

And of course the proxied protocols like http/httpsd need to be allowed to the destinations.

 

This applies to both, a proxy running on the internal or external firewall.

 

To get a proxy working on the internal firewall the external firewall needs policies to allow the required traffic from the internal firewall.

When running the proxy on the external firewall those outgoing policies do not have to be added as outgoing traffic that is locally originated is implicitly allowed.

The easier approach is running the proxy on the external firewall.

 

Best Regards

Labels
Top Kudoed Authors