Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dirkdigs
New Contributor

fortiweb deployment question

hello i have a IIS web server currently connected to dmz interface on a Cisco ASA. 

I will be adding a fortiWEB VM . (Everything is virtual)

DO i setup an interface on my fortiWEB in the same DMZ and then do i need to create a new subnet , set that as a 2nd interface on the fortiWEB and move my IIS web server to this new subnet? 

 

Ii this correct?

 

Also i believe on my fortiWEB i create a virtual server IP using the original IP address of my IIS webserver AKA the old IP address from the DMZ subnet?

 

Thanks ,

2 REPLIES 2
abelio
Valued Contributor

Hello Jason

it depends on deployment mode actually.

 

Assuming you'll go for the most used, reverse-proxy mode, if you configure for instance fortiweb port1 belonging to that DMZ, you'll need renumerate your IIS webservers IP address and connect all these 'behind' another WAF interface.

 

On the hand, if you adopt some of the transparent modes available, you could avoid renumerate, but (maybe) the whole setup became a little bit more complex, using v-bridge.

 

 

 

 

 

 

 

regards




/ Abel

regards / Abel
dirkdigs

thanks for the reply. yes i was going to use reverse proxy mode. 

 

i will re-ip the webserver . thank you .

Labels
Top Kudoed Authors