Technical Tip: How to resolve 'certificate-probe-failed' error for mask-h2.icloud.com
| Description | This article describes how to resolve the 'certificate-probe-failed' error for mask-h2.icloud.com |
| Scope | FortiGate v7.4.x. |
| Solution | In Security Logs -> SSL logs, there are a lot of SSL-anomaly logs for mask-h2.icloud.com
time=""07:15:31""","devid=""FGXXXXXXXXXX""","vd=""FFF""","type=""utm""","subtype=""ssl""", "action=""bypass""","bid=32076206","devname=""IFG""",""","dstepid=101","dsteuid=3", "dstintf=""FFFoutside""","dstintfrole=""lan""","dstip=""17.248.248.123""","dstport=443", "dstuuid=""f84dc972-b00c-51e7-bde1-f5861a210eb0""","dvid=1053","epid=3","euid=3", "eventsubtype=""certificate-probe-failed""","eventtime=1751958931577967864","eventtype=""ssl-anomaly""","hostname=""mask-h2.icloud.com""","id=7524606312588514193","level=""notice""","logid=""1700062306""", "logver=704082795","msg=""SSL connection is bypassed due to unable to retrieve server's certificate""","policyid=94","policytype=""policy""","poluuid=""3ee8b2a2-cea3-51e7-2863-bc943b189f6a""","profile=""custom-cert-inspection""","proto=6","service=""SSL""","sessionid=3361964428","sni=""mask-h2.icloud.com""","srccountry=""Reserved""","srcintf=""XL-FF_inside""","srcintfrole=""lan""","srcip=""10.155.177.74""","srcport=60994","srcuuid=""f77bc4fc-b53b-51e7-eb3a-2c5a21b0b403"""
To check the cause of SSL anomalies, IPS debugs need to be collected:
diagnose debug reset
2025-07-09 14:31:17 [22858@-1]eng_debug_log: Probe info:
This issue is triggered only when Proxy-based inspection is being used and is investigated under known issue: 1141367, and it will be fixed in v7.4.9. Workaround: Allow 'cert-probe-failure' in the SSL/SSH profile that is used in the firewall policy, and add a static URL filter as below:
config firewall ssl-ssh-profile
|

