Solution | FortiGate is capable of performing deep packet inspection (DPI) on traffic destined for major AI applications, including, but not limited to:Â ChatGPT, Gemini, and Copilot.Â
However, a specific configuration is required to ensure inspection works correctly for Microsoft destinations.
Beyond applying the Application Control profile that allows or monitors the Generative AI category or application required, it is necessary to disable the certificate exemption, which is often enabled by default for Microsoft domains, to inspect this traffic successfully. This is achieved by creating a Custom Deep Inspection Profile, removing the 'Microsoft' FQDN, and applying the custom SSL inspection profile to the firewall policy:
 Â Firewall policy sample: Â  Â To check the logs: Security Events -> Logs -> Application Control:
 Â Some applications display this information under Application Details, as shown above, while others require selecting it to view the necessary details:
 Note: There are some caveats when dealing with Microsoft 365 Copilot. The traffic might be identified as Microsoft Portal instead, as Microsoft encapsulates different types of traffic in the same manner: Copilot, Sharepoint, etc. The opposite happens for browser-based and Copilot App, where the traffic is correctly identified and matched as Copilot. This is not a limitation of FortiGate, but of how Microsoft embeds the traffic when using Microsoft 365 Copilot.
|