Hi,
Is there a way to get the real client IP behind the Fortigate Device, by adding the add x-forwarded header? I can see it is possible using FortiWeb, but not using Fortigate in the documentation.
Vinodh
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
None of the fgt devices we manage have web servers behind them, so not familiar any of those load-balancing options -- I was going to just post the same info Ede just posted, but figure I'll include the source material (on load-balancing) in case you need to do more than just enabling that one option...which btw is done via CLI to the VIP itself (not on a VIP group). If you haven't set up anything fancy -- just port-forwarding to a single web server, you might be able to get away with disabling NAT on the firewall policy where you have the VIP set (WAN->web server). Perhaps someone else can chime in here with a better solution.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Thanks a lot mhe
Is it ok if I disable NAT? I afraid it may effects on our live service .
And I have a weird problem. I have multiple websites with different domain names behind my FortiGate. Now even Nat is enabled on "WAN->webserver" policy, I enabled x-forwarder-for in Logformat in apache and then my web server can still get IP client for some websites/virtualhosts.
- If client access via Cloudfront--> FortiGate --> Web server : can get client IP
- If client access to Fortigate direclty --> Web server: canNOT get client IP
- However, only one site which without via Cloudfront still can get client IP
Do you know why this happens?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.