Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JPMfg
New Contributor

FortiProxy explicit proxy, ssl deep inspection and forward proxy

FortiProxy 

 

We have a customer that wants to use FortiProxy but has a requirement that seems to be unsupported:

1.) He must forward to an upstream HTTP proxy for regulatory reasons.

2.) He needs SSL deep inspection on FortiProxy to apply UTM profiles and content inspection rules.
3.) Network topology does not support transparent mode, FortiProxy should use explicit mode.

4.) User-Authentifacation against on premise AD (NTML or Kerberos).

 

FortiProxy does support any of these but fails to support the combination of 1 and 2.

Is there any way to have FortiProxy forward web traffic to an upstream HTTP Proxy with full SSL inspection and UTM features?
Is such a feature even on the Roadmap?

 

It would be a bummer to lose that opportunity.

JPM
JPM
2 REPLIES 2
RBA
Staff
Staff

Point 1 and 2 you would need a forward server config on the FortiProxy or proxy chaining. Refer article How to configure web proxy forwarding ser... - Fortinet Community

JPMfg
New Contributor

Forward server and SSL deep inspection are mutually exclusive.
When you add forwarding server to a rule you must use a ssl profile that does not have any deep-inspection options set.
When you select a deep-inspection SSL profile you cannot set a forwarding server.

These two options are currently mutually exclusive but that is a requirement here :\
I wonder why that limitation exists and if there are any plans on lifting it.

JPM
JPM
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors