Skip to main content
sdebnath
Staff
Staff
February 27, 2026

Troubleshooting Tip: SSH Deep Scan setting is disabled automatically after saving the SSL/SSH inspection profile

  • February 27, 2026
  • 0 replies
  • 641 views
Description This article describes a known issue where SSH Deep Scan cannot be successfully configured in the SSL/SSH inspection profile.
Scope FortiGate low-end models.
Solution

On certain entry-level FortiGate models (such as 40F, 50G, 60F, and 60E) with 2 GB of memory, after upgrading FortiOS from version 7.4.8 to 7.4.10 or 7.4.11, an unexpected behavior is observed where the SSH Deep Scan option under the SSL/SSH inspection profile is no longer retained or cannot be enabled. When attempting to enable it, the feature appears enabled; however, after returning to the same screen, the feature remains disabled.

Result.jpg

 

Additionally, the related CLI commands are no longer available, even though the option is still displayed in the GUI. When attempting to enable the feature through the CLI, the command cannot be found, as shown below.

FGR60F-2 # config firewall ssl-ssh-profile
FGR60F-2 (ssl-ssh-profile) # edit dip-certificate-inspection
new entry 'dip-certificate-inspection' added
FGR60F-2 (dip-certificate-inspection) # config ssh
command parse error before 'ssh'
Command fail. Return code 1
FGR60F-2 (dip-certificate-inspection) # end


This is a known issue affecting certain entry-level FortiGate models running specific FortiOS versions. The issue is scheduled to be resolved in FortiOS v7.6.7 and v8.0.0.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!