Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
renanrdrigues
New Contributor II

questions about creating a DMZ

I need to place some cloud servers inside a DMZ;


The topology is 2 fortigates in different locations;


each unit has 2 ISPs;


The question is, do I need to create 1 DMZ for each ISP?

How would I make this DMZ to use the 4 ISPs?

2 REPLIES 2
sjoshi
Staff
Staff

Hi,

 

On FGT if you want to have a dmz you can setup Virtual IP and enable port forwarding.

Can you brief me more on your requirement. Do you have internal server that is behind the FGT and needs to be access from outside using public IP?

https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/361386/protecting-a-web-server-with-dmz

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
khotanbo1
New Contributor

You shouldn't just chuck web servers into a DMZ if you want them externally accessible. You should only allow specific ports for the Web servers. if ipv4 then nat port forward web ports to an nginx reverse proxy on the web server or use haproxy to direct the traffic accordingly. You should put the web servers in an isolated vlan and only allow ports necessary to other devices on other vlans required.

https://omegle.onl/
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors