Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
matchelo
New Contributor II

reach internal iis web server from outside sub domain

hi everyone 

 

i want to reach my internal iis server from outside using a sub-domain

 

i have used virtual ip adress to map my wan ip adress on my intenal adress server. it works.

But i wan to map the adress (http://ip public adress wan) to a sb domain , to mask my wan adress of my fortigate .

 

i would like to have (http:subdomain.net) to reach the same internal web server. I have redirect the subdomain to (http://ip public adress wan), but it don't work properly.

i need help 

 

5 REPLIES 5
AEK
SuperUser
SuperUser

Hi Matchelo

Why do you need to mask your FG pub IP address? Do you use it for FG management from WAN?

AEK
AEK
matchelo
New Contributor II

yes i often use it to manage my device remotely. so i want to hide this wan address to my web service users

matchelo
New Contributor II

t it possible to buy a domaine name et redirect it to my web server, or map this domaine to my map server???

hbac

Hi @matchelo

 

Yes, you need a public domain name to resolve to the public IP of the FortiGate. It is possible to use FortiGuard DDNS: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-Dynamic-DNS-Fortigate/ta-...

 

Regards, 

AEK

From security prospective it is not recommended to manage FG directly from WAN interface, you should disable it. It is better to access with VPN then manage FG from internal interface.

After that you can use another public IP (as VIP) with another domain name (if you prefer) to access your web server.

AEK
AEK
Labels
Top Kudoed Authors