Hot!FortiWeb 100D Internet Access to Backend Server

Author
khhussnain
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/01/07 23:38:55
  • Status: offline
2019/01/08 00:41:43 (permalink)
0

FortiWeb 100D Internet Access to Backend Server

We have deployed Fortiweb 100D in reverse proxy mode. We want to provide Internet access to backend servers through Foritweb. Applications that are hosted on backend servers are accessing properly using internet. But backend server has no internet connection showing via fortiweb. All virtual servers IP and also all fortinet interfaces IP's are pinging from backend server but the router gateway 192.168.11.5 is not pinging. Please help
#1

8 Replies Related Threads

    khhussnain
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/07 23:38:55
    • Status: offline
    Re: FortiWeb 100D Internet Access to Backend Server 2019/01/08 21:23:56 (permalink)
    0
    Any Update please!!!!
    #2
    khhussnain
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/07 23:38:55
    • Status: offline
    Re: FortiWeb 100D Internet Access to Backend Server 2019/01/08 21:24:57 (permalink)
    0
    Any Update please
    #3
    anasalomari@hotmail.com
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/08 05:09:07
    • Status: offline
    Re: FortiWeb 100D Internet Access to Backend Server 2019/01/08 23:46:34 (permalink)
    0
    FortiWeb can not act as gateway for your servers, it just revers proxy.
    so you need to add tow Ethernet interfaces to your server and add deferente routes inside your server.
    or alternatively  ,you need add L3 device in front of your server and the do  routing on that L3 node.
     
    Anas
     
    #4
    khhussnain
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/07 23:38:55
    • Status: offline
    Re: FortiWeb 100D Internet Access to Backend Server 2019/01/09 01:16:24 (permalink)
    0
    Hello Anas,
     
    Thanks for your reply. So how can I get Internet to backed servers if there is no router. e.g Fortiweb True transparent proxy or Transparent inspection mode. I want to give Internet to backend servers using Fortiweb. I dnt have fortigate in my environment. Can I use policy route for this?

     
    #5
    AlbTR
    New Member
    • Total Posts : 5
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/01/18 08:22:57
    • Status: offline
    Re: FortiWeb 100D Internet Access to Backend Server 2019/01/09 08:45:44 (permalink)
    0
    Hi
    It looks like you will need a forward proxy (not reverse proxy) for that flow.
    Personally never tried, however, in fortiweb you can enable ip forwarding and you can play with simple firewall features that you can find there. There is also snat.  be careful as policy is by default in accept mode. enabling it may breake the client -webserver flow.
    to check /enable ip forwarding  use comands below:
     
    get router setting
    ip-forward : disable
    ip6-forward : disable 
     

    config router setting
    set ip-forward enable
    end
     
     
    Best
    Ab
    post edited by AlbTR - 2019/01/09 08:47:39
    #6
    anasalomari@hotmail.com
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/08 05:09:07
    • Status: offline
    Re: FortiWeb 100D Internet Access to Backend Server 2019/01/09 09:30:42 (permalink)
    0
    hello,
     
    ip-forward is used for the revers traffic note forward traffic.
     
    but i sugest to have 2 ethernets for your server ( ie eth0, eth1)
    configure eth0 without gateway. and make sure that eth0 on the server and fortiweb lan are in the same subnet( layer 2 connectivity)
    and on eth1 define default gateway.
     
    Thanks,
    Anas
     
     
    #7
    hoaiduyen
    New Member
    • Total Posts : 11
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/10/26 02:45:04
    • Location: Việt Nam
    • Status: offline
    Re: FortiWeb 100D Internet Access to Backend Server 2019/01/11 00:34:59 (permalink)
    0
    You can find information in here.
    https://fortinetvn.com/san-pham/fortigate-100d
    Have a nice day !

    Tôi tên là Trần Thị Hoài Duyên. Một cô gái đáng yêu và rất đam mê công việc. Mặc dù con gái tôi, nhưng tôi đam mê công nghệ, đặc biệt là trong mảng bảo mật như thiết bị của Fortinetvn.com
    #8
    khhussnain
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/07 23:38:55
    • Status: offline
    Re: FortiWeb 100D Internet Access to Backend Server 2019/01/14 05:42:03 (permalink)
    0
    Hi Anas,
     
    Sorry I couldn't reply you as I had no Internet access. Yeah I have already implemented the steps you mentioned. Eth0 is for fortiweb/Switch/Servers and Eth1 is direcectly connected to TPLINK Router with DHCP for Internet Access. But my outbound and Inbound traffic won't be filtered by Firewall. So I want Fortiweb to filter Forward proxy traffic as well. Do I must need Fortigate in this environment?
    #9
    Jump to:
    © 2019 APG vNext Commercial Version 5.5