Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ekontos
New Contributor

How do you publish Microsoft Exchange PROPERLY on a Fortigate 60F?

I would like to publish an Exchange 2016 server with a Fortigate but I need to be able to parse the URL's that are used as different URL's send HTTPS traffic to different locations., like OWA, ECP and Active-Sync.   The URL would look something like this: https://www.domain.com/OWA or https://www.domain.com/ecp    This used to work great with ISA Server and I can't believe that it cant' be done with Fortinet.  I DON't want to use an external product like Fortiweb. Any suggestion to resolve this would be great.  I dont want to send all of the HTTP traffic to different sources and there are other servers published with different URL's thru the same IP address. i looked at all of the docs and they try to oversimply it with VIP's but thats not the correct way to do it.

5 REPLIES 5
lobstercreed
Valued Contributor

reddit.com/r/fortinet/comments/9n3ejp/1_public_ip_multiple_service_on_same_port_443/

 

which links to this: help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-load-balancing-52/ldb-http-https-host.htm

 

is the closest thing I can find for you.  I don't think that will work though as you're dealing with the SAME hostname but different URLs (unless you can make it BE different hostnames).  I'm pretty sure you need another product to do that.

poundy

Why do you need to send the traffic to different places? Exchange and Outlook and ActiveSync already deal with this, just send the data to the Exchange server and let them deal with it? 

AlanAdams
New Contributor

To properly publish Microsoft Exchange on a Fortigate 60F while directing HTTPS traffic to different locations, you can consider using a Reverse Proxy approach. Set up a Reverse Proxy server (such as Microsoft Application Request Routing or Nginx) that can route incoming requests based on URL paths (e.g., /OWA, /ecp) to the appropriate Exchange services. Then, configure your Fortigate to forward external traffic to this Reverse Proxy server.

 

This method allows you to route traffic to specific Exchange services based on the URL, similar to your previous setup with ISA Server, without the need for an external product like Fortiweb. It provides more flexibility and control over routing than simply using VIPs.

 

Besides, I know that Microsoft is widely used today. Especially if you are really an expert, you will have quite a lot of customers. My neighbor turns to such a company for services. He says he found a chance to know more about Microsoft office. I think it can be also a new opportunity to you. 

 

I wish you good luck with solving a problem :)

Balfour
New Contributor

As far as software is concerned, only professionals should be contacted. If a person is an expert in his business, he will always have customers. If you have development specialists, but you do not have enough of them, you can read about software development staff augmentation. I think this information can be useful for those who want to develop a company.

AEK
Honored Contributor II

I don't know such feature on FG, I think this is only doable with a reverse proxy.

AEK
AEK
Labels
Top Kudoed Authors