Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zenith
New Contributor

Load-balanced VIP without SSL-Offload?

Hi guys, We' ve looked through the documentation but cannot seem to get a definitive answer on this, any input would be great! Fortigate 100D on FortiOS 5.0. We' d like to load-balance HTTPS across two servers however when configuring the Virtual Server on the Fortigate there doesn' t seem to be an option to do it without SSL Offloading? Our preference would be to terminate the SSL session on the servers themselves, and as we are not doing any real inspection of the traffic I don' t see why the FG cannot just pass the traffic straight through? Thanks! Philip
3 REPLIES 3
Carl_Wallmark
Valued Contributor

Hi Philip, I guess you want to just load balance the traffic ? Try to set the type to " TCP" and change the port to 443, in that case it should ignore the type of traffic and only pay attention to the port which is 443.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Zenith
New Contributor

That would make a lot of sense thank you :), I' ll give it a try now!
Zenith
New Contributor

That did it thanks!
Labels
Top Kudoed Authors