Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Allihopp
New Contributor

Forward traffic to internal network by public domain

Greetings.

I have a FortiGate-80F router and a website with domain somedomain.com

Now I need to set it up, so that whenever a user from WAN loads the website (port 443, https), he will be forwarded to a webserver on my internal network. Also, if the user loads some subdomain, but with same 443 port, his request will be forwarded to another webserver.

In the routers UI > Policy & Objects > VIPs there is a configuration type FQDN, but setting it doesn't do anything, internal websites are still inaccessible from outside.

Please, help solving this problem.

1 Solution
hbac
Staff
Staff

Hi @Allihopp

 

You can use Virtual server instead. After creating the virtual server, you also need to create a firewall policy. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-a-virtual-server/ta-p/194457

 

Regards, 

View solution in original post

3 REPLIES 3
ozkanaltas
Contributor III

Hello @Allihopp ,

 

FortiGate is not able to forward web traffic by domain names. If you want to do this, you need to use a load balancer (FortiADC or a similar product). FQDN-based VIPs are not used for this purpose.

 

If your all websites are deployed on one server. You can forward outside traffic to the inside web server via FortiGate VIP. After that, your server needs to show related websites by domain name.

 

You can review this document "How to redirect outside traffic to inside via VIP".

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Virtual-IP-VIP-port-forwarding-configurati...

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
hbac
Staff
Staff

Hi @Allihopp

 

You can use Virtual server instead. After creating the virtual server, you also need to create a firewall policy. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-a-virtual-server/ta-p/194457

 

Regards, 

Allihopp
New Contributor

Thank you very much.

Labels
Top Kudoed Authors