I need to place some cloud servers inside a DMZ;
The topology is 2 fortigates in different locations;
each unit has 2 ISPs;
The question is, do I need to create 1 DMZ for each ISP?
How would I make this DMZ to use the 4 ISPs?
Hi,
On FGT if you want to have a dmz you can setup Virtual IP and enable port forwarding.
Can you brief me more on your requirement. Do you have internal server that is behind the FGT and needs to be access from outside using public IP?
https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/361386/protecting-a-web-server-with-dmz
You shouldn't just chuck web servers into a DMZ if you want them externally accessible. You should only allow specific ports for the Web servers. if ipv4 then nat port forward web ports to an nginx reverse proxy on the web server or use haproxy to direct the traffic accordingly. You should put the web servers in an isolated vlan and only allow ports necessary to other devices on other vlans required.
User | Count |
---|---|
2624 | |
1393 | |
804 | |
670 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.