- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Web redirect
Hello everyone,
We have a DNS record that currently points to one of our Public IP Addresses.
With a VIP, the traffic is sent to our Big IP F5 where an irule is defined to redirect the traffic to an external public website (https).
I would like to do the same but directly from the Fortigate and not use the our F5.
Can this be done ?
Thanks
- Labels:
-
Firewall policy
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi JF
You should be able to do it with a VIP and a firewall rule.
Add a VIP to map the virtual IP to the real IP (on the required TCP port, like 443 and/or 80), then add firewall rule that allow traffic from ALL (as source) to the VIP (as destination).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello AEK
I tried that and it doesn't work.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you share the configuration? (you can hide the public IP addresses)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I took it out already since it didn't work :)
Thing is, the F5 rule is also presenting a certificate on the redirect (wildcard) and this can't be done with a VIP... So I also tried with a Virtual Server... but no luck there either.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That's right, you can present a certificate using VS. But we may help further if you can share the configuration (VS & firewall rule).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'll redo the config and share it once I'm done
Cheers
JF
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is what I want to do (Visual fix is easier)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Now with the diagram I understand better.
Usually VIP is used for incoming traffic, from outside to inside, like when you publish a server from DMZ to internet.
I see here you want to access a public server through a VIP. So my question is why you want to use a VIP? Normally you just access the external web server directly using its public IP, right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I know...
But we have a requirement for that...
We currently have users that use "anothercompany.ourcompany.com" and this is redirected to "anotherwebsite.anothercompany.com" ... it was setup to facilitate things for our users...
We'll soon retire those F5... Need this to be done by the Fortigate if possible.
That's the reason :)
JF
