Technical Tip : 'SSL_BAD_MAC_ERROR_READ' Firefox browser error when deep-inspection is enabled
| Description | This article describes the error 'SSL_BAD_MAC_ERROR_READ' being encountered in the Firefox browser whenever deep-packet inspection is enabled. |
| Scope | FortiGate v7.2, v7.4, and v7.6 |
| Solution | Whenever a (TLS 1.3) website is accessed for the very first time, an error code: 'SSL_ERROR_BAD_MAC_READ' in Firefox browser may be encountered. With further details saying that, 'An error occurred during a connection to <website URL>. SSL received a record with an incorrect Message Authentication Code.'.
A simple refresh of the webpage will load the website completely with no issue. The error is due to the TLS 1.3 session failing after certificate verification.
IPS debug output:
[39079441,369]: [INFO] HANDSHAKE message: type=COMPRESSED_CERT(25), len=2303
If the issue is encountered, the IPS engine must be updated to a recent build. IPS engines that fixed the issue have been released in the following FortiOS versions.
Upgrade to these versions for a fix:
|

