Hello PAM admins
FortiPAM 1.4.1.
I'm very new in FortiPAM and I have questions regarding Web launcher.
When I'm in company's local network all works fine, Web launcher, RDP launcher and SSH launcher.
However when I'm outside and connect from public IP and try run Web launcher it doesn't work, while SSH launcher and RDP launcher still work fine.
I noticed that for both RDP and SSH launcher, PAM opens the browser tab with address bar contains a public address like https://pam.mycompany.com/someaddress.
While for Web launcher it opens the private IP of the target, which naturally can't work from WAN without some proxy on the client.
If I'm not wrong I think it needs FortiClient in order to work, right?
So my question:
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Abdelkrim,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello Abdelkrim,
We are still looking for someone to help you.
We will come back to you ASAP.
Regards,
Thanks Antony for your support
Nothing urgent for now.
Thank you Abdelkrim :)!
Hi,
In the target of the secret under advanced settings, have you enabled "Web proxy" and "Domain list" with access mode as "proxy" and then set up a FQDN or IP list?
https://docs.fortinet.com/document/fortipam/1.4.1/administration-guide/460943/web-proxy
Hi Chris
Thanks for your response.
I'll try this method and comeback with the result.
Any update?
FortiProduct (proxy enabled) works fine, but when I create a new target as described on the admin guide and above Examples doc, it doesn't works.
I'm still new in FPAM and just beginner in troubleshooting. I'll keep you updated if I have any interesting result.
For info, since I don't have FCT EMS, I had to install FortiPAM Agent on the client, which is only available for Windows :(
Hello Abdelkrim,
Here are some steps to troubleshooting:
1. Ensure that FortiPAM can access to the internal web portal, if case FQDN ,FortiPAM can resolve .
2. Make sure you have enabled web proxy on the interface. https://docs.fortinet.com/document/fortipam/1.4.0/examples/390911/enabling-the-web-proxy-feature
3. Create secret target & enable Web Proxy . https://docs.fortinet.com/document/fortipam/1.4.0/examples/2487/creating-a-secret-target-with-web-pr...
4. Add a secret target to your secret.
5. if FortiPAM is behind the FortiGate or other firewall vendor . https://docs.fortinet.com/document/fortipam/1.4.0/examples/168674/fortipam-behind-a-fortigate-device
6. Create DNAT on the firewall and allow all ports , do not specify only FortiPAM's port (FortiPAM's portal) .
Thanks,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.