Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Martasss
New Contributor

Two different websites (domains) on two different internall IIS servers on same port 443

Hello,
I have a small problem but I didn't find a solution here. (I´m not expert)
I have two domains eg "one.domainname.com" and "two.domainname.com"
Both are routed to the internal network via 2 separate policies and two virtual IPs to two different IIS servers with two different internal addresses:
one.domainname.com -> 172.10.1.2 (VIP dest1)
two.domainname.com -> 172.10.1.3 (VIP dest2)
But on the same SSL port 443

VIPs are set:
WAN IP -> 172.10.1.2 with port forwarding "one to one" 443->443 (the second is the same only with a different IP address and name)

There are one policy for each VIP:
Outside int->Inside int
Source ALL, Destination dest1 (dest2 for second policy), Service ALL, SSL certificate inspection

The SSL port of the firewall is changed to different

If I enter "one.domainname.com" from the outside, the page from the internal IIS server 172.10.1.2 opens normally, but if I enter "two.domainname.com", I don't get to it, because it is not directed to the correct server, but instead to 172.10.1.3 it is still routed to 172.10.1.2 where it is not.

When I had both websites on the same server, there was no problem, but now it had to change and I don't know how to do it - so far I have set routing via port (for dest2 I changed the external port and added it to the address) and at that moment it correctly opens two.domainname.com from server 172.10.1.3 (instead of trying from .2).

How to solve this, so that I don't have to have a port in the address and traffic is routed correctly?

2 REPLIES 2
adambomb1219
SuperUser
SuperUser

I don't think the VIP is aware of the domain name?  IMHO this isn't possible without using a different public IP or a different port.

anignan
Staff
Staff

Hi @Martasss ,

 

I think for this you can use virtual server feature and play with HTTP host header.. 

Check this if that helps: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setting-up-a-VIP-load-balance-with-HTTP-ho...

 

Abdel

Labels
Top Kudoed Authors