Hi guys,
I've set up a 100D to load balance HTTPS traffic between two real servers. So, I have one virtual server of type HTTPS, SSL offloading Client<->FortiGate and two real servers. But the problem is that users have to type in https://www.webserveraddress.dom every time they want to access my website.
What I would like is to automatically redirect their HTTP requests (i.e. http://www.webserveraddress.dom) to HTTPS (i.e. https://www.webserveraddress.dom).
Is there any way to do this on FGT-100D?
Thanks!
NSE 7
All oppinions/statements written here are my own.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
HI,
Your requirement can be achieved with Fortiweb but with Fortigate HTTP to HTTPS redirection is not possible.
I think you need a FortiWeb for this case. Or other dedicated load balancer (F5, A10, Kemp, etc.) / WAF that supports SSL offloading.
Hi,
FortiGate-100D does support SSL Offloading, and I've created a virtual server of HTTPS type. This works great. The certificate is being presented to the client by the FGT (SSL offloading is Client<->FortiGate), and the connections are being load balanced between two real servers.
But, it works only if the client types in https://www.serveraddres.lab in the address bar. If they go to the http://www.serveraddress.lab, they get nothing.
What I would like is that FortiGate automatically redirects all clients from http to https. It is a simple thing to do in TMG.
NSE 7
All oppinions/statements written here are my own.
HI,
Your requirement can be achieved with Fortiweb but with Fortigate HTTP to HTTPS redirection is not possible.
OK, thank you... It's a shame, really. It's only a minor feature, and I don't think it would be hard to implement, too. Especially when you consider that FGT is perfectly capable to automatically redirect administrative users from HTTP to HTTPS, when they try to login.
Thanks anyway, it's a correct answer - even though I don't like it. :)
NSE 7
All oppinions/statements written here are my own.
HTTP to HTTPS redirect was added to 6.2.1 Code you can terminate 443 on the fortigate or just pass 443 all the way to the server. This link shows how to terminate/offload 443 on the fortigate https://docs.fortinet.com...ect-for-load-balancing here is a link to offloading https://help.fortinet.com...db-ssl-tls-offload.htm if you want to just pass 443 to the server and not terminate the session on the fortigate edit the vip "virtual-server-https" ---> set server-type tcp
you can also redirect other ports like 8080 using http edit "virtual-server-http" set extport 80 to set extport 8080 be sure to use proxy mode
I know, very old post, but good news...
Starting with FortiOS 6.2.1, you can configure a virtual server with HTTP to HTTPS redirect enabled
https://docs.fortinet.com...ect-for-load-balancing
[Edit]
sorry, allready posted :)
________________________________________________________
--- NSE 4 ---
________________________________________________________
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1643 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.