Fortinet Reverse Proxy for IIS
Budget: ₹1,500 – ₹12,500 INR
I need my FortiGate firewall configured as a secure reverse proxy so that two internal IIS web servers are reachable over the internet via HTTPS. Both sites already have valid SSL certificates, so the task focuses on designing the virtual servers, SSL off-loading or re-encryption as required, address and service objects, and any policy tweaks needed to make the traffic flow cleanly while retaining Fortinet best-practice hardening.
Current situation
• Two IIS servers sit on separate internal VLANs.
• Public DNS records are in place.
• SSL certificates are installed on the IIS hosts and can be exported in PFX format if you prefer termination on the firewall.
Scope of work
1. Review the existing FortiGate configuration (VPNs, policies, address objects).
2. Design the reverse-proxy / virtual-server setup for both sites, mapping external FQDNs to internal hosts.
3. Import and bind the existing certificates or advise if firewall-side termination makes more sense.
4. Implement and test end-to-end connectivity (HTTP-to-HTTPS redirection, header preservation, HSTS, etc.).
5. Document the final configuration so I can reproduce it on future boxes.
Acceptance criteria
• Both websites load externally over HTTPS with valid certificates and no mixed-content warnings.
• Internal hosts remain unreachable directly from the internet.
• No service interruption to other live policies on the FortiGate.
• A brief handover document outlining objects, policies, and rollback steps.
Remote access to the firewall and servers will be provided over Remote Access. This is a focused task; no IP whitelisting or user authentication layers are required beyond what the FortiGate already enforces.
If you have deep experience with FortiOS reverse proxy features and IIS, I’m ready to get started right away.
Current situation
• Two IIS servers sit on separate internal VLANs.
• Public DNS records are in place.
• SSL certificates are installed on the IIS hosts and can be exported in PFX format if you prefer termination on the firewall.
Scope of work
1. Review the existing FortiGate configuration (VPNs, policies, address objects).
2. Design the reverse-proxy / virtual-server setup for both sites, mapping external FQDNs to internal hosts.
3. Import and bind the existing certificates or advise if firewall-side termination makes more sense.
4. Implement and test end-to-end connectivity (HTTP-to-HTTPS redirection, header preservation, HSTS, etc.).
5. Document the final configuration so I can reproduce it on future boxes.
Acceptance criteria
• Both websites load externally over HTTPS with valid certificates and no mixed-content warnings.
• Internal hosts remain unreachable directly from the internet.
• No service interruption to other live policies on the FortiGate.
• A brief handover document outlining objects, policies, and rollback steps.
Remote access to the firewall and servers will be provided over Remote Access. This is a focused task; no IP whitelisting or user authentication layers are required beyond what the FortiGate already enforces.
If you have deep experience with FortiOS reverse proxy features and IIS, I’m ready to get started right away.