Hello Experts, Can someone please confirm that if we have a regular VIP
with an Public IP address, other than the Firewall external interface
IP, will return traffic from the exposed server will use the same Public
IP from the VIP? If not, do I need ...
Hello all, I am looking for a lab set up to test server load balancing.
The http will be terminated on the firewall to redirect to https, so
inside real servers will only have 443 port listening on. The member
servers of each such VIP/Virtual Server ...
Hello forum members and experts, I need to use an additional Public IP
block of /29 over /30 transport block. Since this /29 block wont be
assigned to any interface, but will just be used on VIPs to map to the
inside servers, and thus no L2 / ARP on ...
Hi All, In configuring SD-WAN (WAN load balancing), under "configure
system-wan-link", what will be difference between "set
fail-alert-interfaces" and "configure fail-alert-interfaces"?
Hi All, There is a requirement wherein I need to setup two FGTs into a
VRRP pair rather than creating a cluster. In this situation, do we have
option to utilize HA links, rather than having to upon the LAN switches
to provide a path for VRRP heartbea...
Thank you so much for your advice and confirmation. I was confused as to
what will be the outbound Public IP if the server in question initiates
the traffic. And as per your clarification, if it is 1:1 map, then it
will use the same VIP. For port for...
I was able to download a VM of FortiGate and install it to validate what
options are available. I was able to confirm that I can create ping and
https connect health checks and then under Virtual server section, where
I need to specify the VIP, it di...
Thank you so much Toshi Esumi for confirming my logic. I did spend time
to search thru this forum as well as did Google search but I did not
find specific question and specific response to it. Most will talk that
yes this is standard practice to rout...
Sorry for posting in the old thread. 1. Is there a way to force master
unit to become backup if attached ISP circuit on master goes down
(interface monitoring or virtual wan link, health check)? In my case, I
will be using two ISPs on each FGT, so SD...
Hi, You might be able to force the particular service / server to use
one ISP to go to the particular provider, using SD-WAN policy rules,
while all other traffic can use load balancing.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.