Skip to main content
dingjerry_FTNT
Staff
Staff
July 23, 2025

Technical Tip: How to detect HTTPS-in-HTTP trafficon FortiProxy

  • July 23, 2025
  • 0 replies
  • 208 views
Description This article describes how to detect HTTPS-in-HTTP traffic on FortiProxy.
Scope FortiProxy v7.0.7 or above.
Solution

Before v7.0.7,  it was not possible to detect HTTPS-in-HTTP traffic.

In an explicit web proxy, if the 'detect-https-in-http-request' setting is enabled, HTTP GET/POST requests sent to the FortiProxy will be detected and passed instead of blocked.

 

This setting was introduced starting from v7.0.7 in the 'config web-proxy explicit-proxy' section. Starting from v7.4.1, this setting has been moved to the 'config firewall policy' section.

 

For more info about the usage and syntax, check the CLI reference guide:

FortiProxy 7.0.7 CLI Reference - "config web-proxy explicit-proxy" 

FortiProxy 7.4.1 CLI Reference - "config firewall policy" 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!