Technical Tip: FortiGate fails to block HTTPS websites due to encrypted traffic
| Description | This article describes how to troubleshoot and resolve issues where FortiGate fails to block adult or restricted HTTPS websites due to encrypted traffic (HTTPS / TLS 1.3 ECH). |
| Scope | FortiGate. |
| Solution | Administrators may observe that FortiGate fails to block adult or restricted websites even when Web Filter and URL Filter profiles are properly configured. Symptoms:
Root Cause: Most adult sites and large CDN-hosted domains (e.g., Cloudflare, Akamai) use HTTPS with Encrypted Client Hello (ECH). Without Deep SSL Inspection, FortiGate cannot decrypt and read the true URL or hostname inside the TLS 1.3 session, resulting in failed filtering.
Note: SNI may still appear in the Encrypted Client Hello, but this is the outer SNI, which is sent in clear text. Refer to this article for more info: Technical Tip: How to block TLS 1.3 Encrypted Client Hello (ECH) in FortiGate firewalls.
*cloudflare-ech* *whos.amung*
|
