Hi,
Is there a way to get the real client IP behind the Fortigate Device, by adding the add x-forwarded header? I can see it is possible using FortiWeb, but not using Fortigate in the documentation.
Vinodh
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
None of the fgt devices we manage have web servers behind them, so not familiar any of those load-balancing options -- I was going to just post the same info Ede just posted, but figure I'll include the source material (on load-balancing) in case you need to do more than just enabling that one option...which btw is done via CLI to the VIP itself (not on a VIP group). If you haven't set up anything fancy -- just port-forwarding to a single web server, you might be able to get away with disabling NAT on the firewall policy where you have the VIP set (WAN->web server). Perhaps someone else can chime in here with a better solution.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
See page 22 of the Load Balancing Handbook.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
This is a CLI command only option:
config firewall vip
edit <name_str>
set http-ip-header {enable | disable}
Hi,
Thank you guys for replying. Do I need to enable load balancing on a particular Virtual IP groupto get this option enabled? When I try to edit the Virtual IP group, I am not getting the option 'http-ip-header'.
ede_pfau wrote:This is a CLI command only option:
config firewall vip
edit <name_str>
set http-ip-header {enable | disable}
Vinodh
None of the fgt devices we manage have web servers behind them, so not familiar any of those load-balancing options -- I was going to just post the same info Ede just posted, but figure I'll include the source material (on load-balancing) in case you need to do more than just enabling that one option...which btw is done via CLI to the VIP itself (not on a VIP group). If you haven't set up anything fancy -- just port-forwarding to a single web server, you might be able to get away with disabling NAT on the firewall policy where you have the VIP set (WAN->web server). Perhaps someone else can chime in here with a better solution.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Hi Dave,
Yes, There is nothing fancy, and just as you had mentioned, I am just port forwarding the IP to a single webserver. I realized I had to disable NAT, but decided to see if there was a better solution. Thanks for your help!
Vinodh
Dave Hall wrote:None of the fgt devices we manage have web servers behind them, so not familiar any of those load-balancing options -- I was going to just post the same info Ede just posted, but figure I'll include the source material (on load-balancing) in case you need to do more than just enabling that one option...which btw is done via CLI to the VIP itself (not on a VIP group). If you haven't set up anything fancy -- just port-forwarding to a single web server, you might be able to get away with disabling NAT on the firewall policy where you have the VIP set (WAN->web server). Perhaps someone else can chime in here with a better solution.
[size="4"]I would like to ask a similar thing as in the subject. I have a linux server on the network and would like to be able to see from what public addresses were trying to log in to SSH on port 22. All these addresses are present in the address of the router and I am interested in seeing the real a adresses how can this be done?[/size]
set http-ip-header {enable | disable}
is NOT an available option!
Seb
Hello
I am new with FortiGate.I have the same problem with AWS FortiGate 5.6.3 Mode NAT. I put our web servers behind FortiGate and now web server just show FortiGate IP as client IP on log.
Do you have any advise or experience for this?
Thanks
Disable NAT on the Policy WAN -> Webserver
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.