- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hosting multiple Public URLs on a external interface IP on Fortigate
I am trying to host multiple Application URLs on Fortigate's external interface public IP... can i configure it using Virtual IPs ? i need to use single public IP with same listener.
If i create as follows will it work ?
1) website1@abc.com as virtual IP1 and website2@def.com as virtual IP2 with both of them having same external public ip and same port
2) create 2 policy for each website and tag certificate via ssl-inspection
any help is appreciated.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check this link.
In summary you can do it but you can't use one firewall rule for each server, since the firewall rule must have the VS object as destination.
For advanced features like that you need a dedicated WAF like FortiWeb.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks for the link.. is it possible to do such configuration when hosting different urls on the same external ip but both with different named certificates ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you use same IP and same port (e.g.: 443) then it seems not possible with FG.
Either use another port (e.g.: 8443 for the second) or use a SSL certificate with multiple alternate names (or wildcard).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
