Hi; Can I have the FortiGate insert an X-Forwarded-For header only if
the HTTP method is GET or CONNECT. Basically I have a virtual server of
type http set up with "Preserve Client IP". It is load balancing traffic
originating from browsers "with exp...
Hi; I have a Fortigate firewall that is setup to "preserve client IP" at
a virtual server defined on it. This virtual server load balances
traffic destined to two explicit forward proxies on port 8080. When the
explicit proxy traffic is http, XFF is ...
Hi; I would like to have Fortigate insert an X-Forwarded-For header by
using the "Preserve Client IP" option available with a load balancing
virtual server. My question is: If there is an upstream device that
inserted the XFF header before the Fortig...
Hi;I would like to have Fortigate insert an X-Forwarded-For header by
using the "Preserve Client IP" option available with a load balancing
virtual server. My aim, however, is to replace any X-Forwarded-For
header's value that was inserted by a prece...
Hi; If I have configured a load balancing virtual server on a FortiGate
device, can I gather statistics about the maximum number of concurrent
TCP sessions that has been experienced by that virtual server at some
instance of time. KindlyWasfi
in my case, the FortiGate virtual server is not doing any SSL
decryption. It however, adds the XFF header in the http datagram
conveying the client hello.
Thank you for your reply Emnoc. I don't have config firewall ssl-server
My virtual server is very basic. It is doing round robin load balancing
with source IP hash persistence. However, since it does source IP
Natting, the original client IP is not s...
Hi Thomas; You are not being rude. I think it was lazy of me to post on
the FortiAuthenticator Forum in the first place. I couldn't find the
FortiGate forum, so I assumed that I can post on the FortiAuthenticator,
which wasn't appropriate. Sorry. I w...
Hi Yuri the FortiGate Firewall will not be load balancing. It is just
acting as an Internet gateway doing Source IP Natting. Furthermore, it
will not be handling https but rather http only, thus no need for
loading the certificate on the FortiGate. I...