We have deployed Fortiweb 100D in reverse proxy mode. We want to provide Internet access to backend servers through Foritweb. Applications that are hosted on backend servers are accessing properly using internet. But backend server has no internet connection showing via fortiweb. All virtual servers IP and also all fortinet interfaces IP's are pinging from backend server but the router gateway 192.168.11.5 is not pinging. Please help
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Any Update please!!!!
Any Update please
FortiWeb can not act as gateway for your servers, it just revers proxy.
so you need to add tow Ethernet interfaces to your server and add deferente routes inside your server.
or alternatively ,you need add L3 device in front of your server and the do routing on that L3 node.
Anas
Hello Anas,
Thanks for your reply. So how can I get Internet to backed servers if there is no router. e.g Fortiweb True transparent proxy or Transparent inspection mode. I want to give Internet to backend servers using Fortiweb. I dnt have fortigate in my environment. Can I use policy route for this?
Hi
It looks like you will need a forward proxy (not reverse proxy) for that flow.
Personally never tried, however, in fortiweb you can enable ip forwarding and you can play with simple firewall features that you can find there. There is also snat. be careful as policy is by default in accept mode. enabling it may breake the client -webserver flow.
to check /enable ip forwarding use comands below:
get router setting
ip-forward : disable
ip6-forward : disable
config router setting set ip-forward enable end
Best
Ab
hello,
ip-forward is used for the revers traffic note forward traffic.
but i sugest to have 2 ethernets for your server ( ie eth0, eth1)
configure eth0 without gateway. and make sure that eth0 on the server and fortiweb lan are in the same subnet( layer 2 connectivity)
and on eth1 define default gateway.
Thanks,
Anas
Hi Anas,
Sorry I couldn't reply you as I had no Internet access. Yeah I have already implemented the steps you mentioned. Eth0 is for fortiweb/Switch/Servers and Eth1 is direcectly connected to TPLINK Router with DHCP for Internet Access. But my outbound and Inbound traffic won't be filtered by Firewall. So I want Fortiweb to filter Forward proxy traffic as well. Do I must need Fortigate in this environment?
Hi Anas,
Any Update?
I have executed following commands. Now I am able to ping Gateway of TP-LINK Router from Backend servers but still unable to get through Internet? Any thoughts
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.