Hello,
I have these 2 doubts:
1- If I want to protect a web server NATed to internet , I can do this only with a normal VIP and SSL inspection , right?
I mean I do NOT need to enable Load Balance feature like this example:
2- And if I want to protect for example an email server (encrypted traffic) in the SSL inspection profile ,under
"Protocol Port Mapping" I have these 2 choices right:
- select "Inspect all ports"
or
- on "HTTPS" add the ports that I want (i.e 25,587,465)
With any of these 2 I would be protecting my email server from malware and other attacks (with AV/IPS profiles) right?
Thank you in advace
Regards
Hi Kamarale
Hello AEK, thank you for the reply.
Just to undestand it correctly. What would I gain if I use VS vs VIP if I am only protecting 1 web server (http/https)? I mean I am not interested in LB.
Normal VIP with inbound SSL inspection vs VirtualServer with inbound SSL inspection
Thank you
Regards
Hi Kamarale
Honestly when I protect Web servers with FGT's WAF I didn't try it with VIP, I always do it with VS, since this is the recommendation from Fortinet. I even don't know if it will fully work with VIP.
But at least with VS you can select SSL offloading mode (Client-FGT or Full), preserve client IP, redirect HTTP to HTTPS, and some HTTP header manipulation.
Additional info in this Tech Tip:
Hope it helps.
User | Count |
---|---|
2568 | |
1362 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.