Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hun
New Contributor

NAT/Proxy 443 on domain controllers to outside web server

How can I redirect Port 443 only to a different IP with the FortiGate?

 

Domain Controllers are in separate subnet, and all requests except port 443 should go to the real IP.

 

Port 443 should be redirected to an external webserver.

 

(for context: AD set up with split DNS, domain.com internal AD, and the same domain.com externally and we can't change or AD name, using www is not an option)

2 REPLIES 2
AEK
SuperUser
SuperUser

If I understand well your request I think you need policy routes.

https://docs.fortinet.com/document/fortigate/7.4.5/administration-guide/144044

 

AEK
AEK
ebilcari
Staff
Staff

Are the DCs already reached through a VIP? If the VIP is in use than the IP of the real servers behind can be easily added/changed. When dealing with AD/DC I would prefer to go with a DNS approach (new sub/domain) as a cleaner solution and not create VIPs.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors