Created on 07-12-2011 08:39 AM
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I' ve added several Wan IP address on the wan1 interface.you don' t need to do that; Define your wan by choosing one from your public ips You can use another IP for your webserver (or the same one if you wish) This article can help you: http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=11765&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=21326709&stateId=0%200%2021328487 Also check: webserver' s default gateway, does it points to DMZ IP ? good luck
regards
/ Abel
Created on 07-13-2011 03:40 AM
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
a) is possible to nat ONE public ip address (configured onto the WAN1 interface) to many private IP?yes, and you could also balance traffic between internal servers hosting same websites. (if you use exactly the same IP configured in wan interface - i dunno why if you have 30 ip numbers available-, you' ll have to take care about firewall administrative ports)
b) even if one server host several web site of different customers, is possible to reach these web site using only one public IP?yes; virtualhosting is a DNS / webserver topic. but your below example is more complex than that:
example: a) i have 3 domain registered onto my dns server: domain-1.com domain-2.com domain-3.com the DNS server map each domain on one and same public ip (WAN1): 2.10.10.100 the websites of the 3 domains are on different webserver with a unique ip (DMZ1): 192.168.0.200/201/202 the FTG will be able to catch the request (www.domain-X.com) and redirect it to the right IPhummm, no; not yet; i guess you' re thinking in msisa server in this point. you can define a VIP 2.10.10.100:80 -> 192.168.0.200:80 and host on 192.168.0.200:80 as many virtualdomains as you wish. but you cannot send also the same port80 to another webserver hosting another website; you' ll need use another ports, ie: 2.10.10.100:81 -> 192.168.0.201:80
b) i have 2 domain registered onto my dns server: domain-1.com domain-2.com the websites of these two domain are on the same server with IP (DMZ1): 192.168.0.99 the DNS server map each domain on one and same public ip (WAN1): 2.10.10.100 the FTG will be able to catch the request (www.domain-X.com) and redirect it to the server passing the domain requestthat' s the usual virtual hosting; no problem with that; strictly speaking, the FGT doesn' t catch the request www.domainX.com, it merely forward the packet by IP to the internal webserver; DNS and Apache/IIS do the rest. regards
regards
/ Abel
Created on 07-25-2011 09:39 AM
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Created on 08-11-2011 04:27 AM
Created on 08-11-2011 06:24 AM
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.