Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BrianV
New Contributor

Redirect HTTP Traffic to Explicit Proxy (Can't use WCCP)

I have an explicit proxy in the cloud. I want to redirect internal HTTP traffic from a select few clients to that explicit proxy transparently. This is possible on Sonicwall, ASAs, Juniper, Checkpoint, etc., but I cannot find a way to policy route traffic to the cloud proxy with my Fortigate. I cannot use WCCP as the proxy is in the cloud and that proxy can't be configured in a WCCP service group.

 

I'm able to route traffic to another cloud proxy that is connected via an IPSec tunnel with this Fortigate so that routing works, but for this specific cloud hosted proxy, I cannot use IPSec.

 

Is this possible in any way with a Fortigate? I have an 80C running 5.2.4.

5 REPLIES 5
Jeff_FTNT
Staff
Staff

FGT support explicit proxy, you may set up explicit proxy on FGT and use "Proxy chaining"  to forward  traffic to "web proxy forwarding servers" .

BrianV

I'm familiar with proxy chaining, I'm actually trying to test specifically HTTP redirection, I'll just use a different edge device, but it's good to know I can go that route.

 

Thanks

emnoc
Esteemed Contributor III

Qs

 

So if the ASA Sonicwall can do this , how are they doing it?

 

1>

I would think a PAC/WPAD  deployment would give you want and with the cloud proxy for the handfull of clients. You can use  identity and authorization for the clients.

 

2>

You can also build a  reverse  virt-server if you have multiple proxies and need to have HA and publish the internal vip for the  client proxy address.

 

Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
BrianV
New Contributor

They support a feature called HTTP Redirection, it's fairly common. I work for a proxy manufacturer, so this is more for testing, but it seems it's not possible with Fortigate. The key point is a lightweight and easy transparent method. IPSec works, but it's not as lightweight as GRE, redirection/port forwarding.

 

That said, if I configure the Fortigate explicit proxy, can I use it as an interface and then create policy routes to essentially use the explicit proxy transparently (which is sort of not an explicit proxy), but I'm not looking for another explicit proxy and then chaining/forwarding, I'm trying to see if there's a non-IPSec method with Fortigate.

emnoc
Esteemed Contributor III

Fair

 

On the question(s), yes you can set a  explicit proxy with rules. You could even conduct identity  fwpolicies for user access if so required.

 

They support a feature called HTTP Redirection

 

 

btw A HTTP redirection is not a proxy.  

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors