Hello everyone,
I'm trying to configure a virtual server of HTTPS type on FGT-90D, but apparently, this model does not support SSL offloading. :(
Does anyone have some creative idea on how can I achieve the same effect (FGT to distribute SSL certificate and establish secure connections with clients, load-balancing their requests between two application servers) on the FGT-90D, like illustrated?
Is there no way to enable SSL offloading on this model? Why does it not support it?
Thanks,
Slavko
NSE 7
All oppinions/statements written here are my own.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
There's a post about the exact same issues and a FGT60D, I can only suggest a SLB device or a opensource linux solution. A FGT90D is a SMB entry level device.
Ken
PCNSE
NSE
StrongSwan
Hi enmon,
I know, that is my thread. :) I opened a new one, because I was hoping I'll get some ideas if I broaden the question a little.
What bothers me is that FGT-80D supports SSL offloading and the 90D does not. I know that 80D has much less ports, but it is still an SMB device, just like 90D.
Anyway, I guess I'll try to find my solution behind the FGT.
Thanks!
NSE 7
All oppinions/statements written here are my own.
There is a big difference between the 80D and 90D,
The 80D has a real CPU while the 90D is SoC CPU. And at the moment the SoC CPU is way to slow for performing SSL offloading. Maybe that will change with the new SoC v3.
FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C
ditto
Maybe you can ask fortinet sales to see what they are going to offer in the future, but if you need SSL_OFF-loading now, you will need to explore different options. A FGT60D which is a great firewall btw, is NOT up to par for SSL-offloading or others SLB features that you would expect from a dedicate SLB.
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.