Troubleshooting Tip: FortiGate does not send the Certificate chain (Handshake_Type=Certificate) on connection to VIP in FlowMode
| Description | This article describes the use of multiple certificates in an SSL profile in replace mode, allowing multiple sites to be deployed on the same protected server IP address. The SSL inspection is going to be based on matching the SNI in the certificate.
But in this scenario, most of the TLS/SSL connection fails against a VIP ('NAT-181.13.111.19:443/TCP'). |
| Scope | FortiOS v7.2.10,build1706. IPS Attack Engine 7.00356. |
| Solution | Configuration:
config firewall vip
config firewall ssl-ssh-profile
config firewall policy
TLS-Handshake fails:
Expected behavior: Gets the 'Certificates' from FortiGate, based on the SNI connection requested by Client.
Solution: Upgrade IPS engine to build v7.0364. |


