Skip to main content

Reverse proxy

Network > Reverse Proxy publishes web applications that live on your internal network. Visitors connect to the firewall over HTTPS, and the firewall forwards their requests to the internal server. This lets you publish several sites behind one public address and terminate encryption in one place.

The reverse proxy works only on TCP port 443 (HTTPS).

Requirements

  • TCP port 443 must be open and reachable on the WAN. If it is not, the page tells you and asks you to check your rules in Firewall rules.
  • A valid certificate for the names you publish. Configure certificates in Certificates; the page reminds you when none is configured.

Creating a rule

FieldMeaning
MatchA site name (a fully qualified domain name) or a resource path that starts with /
DestinationThe internal address to forward to, for example http://server:8080/app
CertificateThe certificate presented to visitors
Allowed networksOptional. Only these IPv4 or IPv6 networks can use the rule

Rules that match a site name are used for whole sites. Rules that match a path publish one part of a site.

Tips

  • Restrict administrative applications with Allowed networks.
  • Test with a browser from outside, and check the Logs if a rule does not answer.
  • Remember that the firewall web interface also uses port 443. A published name must not clash with the name that reaches the firewall itself.