Automatic HTTP-to-HTTPS redirection should be enabled when users must be forced onto encrypted communication, especially for applications that process logins, credentials, payment data, personal data, or other sensitive information. HTTP sends traffic without transport encryption, which exposes users to interception, credential theft, session hijacking, and downgrade-style risk. FortiWeb can redirect HTTP requests to HTTPS so users who type or follow an insecure HTTP URL are automatically moved to the secure version of the application. Keeping both HTTP and HTTPS available for flexibility weakens security. Static sites without sensitive data may not require this control. A back-end server using only HTTP is a separate SSL offloading design issue and does not justify leaving client-side traffic unencrypted.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit