Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tabish
New Contributor

Why we need enable lan to wan in Firewall policy when we are defining lan to wan in Explicit proxy

Hi Team,

 

We are implementing proxy policy with fsso but the issue is why we need to enable lan to wan in Firewall policy when we are defining lan to wan in Explicit proxy. Will not end system which are authenticated via fsso will reach to internet if we just mention policy in explicit only. Also when we disable traffic to Wan in normal policy internet does not work.

Please suggest!

2 REPLIES 2
spoojary
Staff
Staff

Even when clients are configured to use an explicit proxy, some traffic might not be explicitly directed to the proxy server. For example, certain applications or protocols might bypass the proxy settings or use direct connections.  If there is no LAN to WAN firewall policy that allows traffic, authenticated users might not reach the internet for these direct connections or fallback scenarios.

Siddhanth Poojary
Tabish

Hi Siddhanth,

Thank you for following up!

 

It make sense partially but my main concern is after disabling normal Lan to Wan why my users does not go to internet for small traffic like google.com, facebook.com that use https protocol even though same has been allowed in proxy policy. But after I enable lan to wan user can reach to internet and logs show the traffic is going through proxy policy.

Please advise on this.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors