Skip to main content
Troubleshooter_73
Explorer
December 4, 2019
Question

Application visible also with Certificate Inspection only?

  • December 4, 2019
  • 1 reply
  • 2677 views

Hi Community, a short question maybe a short answer?

I know the difference between Deep Inspection and Certificate Inspection. But I've struggled on a customers question:

How the Fortigate is able to detect a specific Application Signature (i.e. Whats App Web instead of Whats App Messaging) if I only use Certificate Inspection? The Packets are both encrypted in SSL at Port 443 and if I understand it right, Certificate Inspection only checks the CN in the Certificate? But if I use FortiView I'm able to see which Application is used by the User.

How they do that? The traffic is encrypted and the system shouldn't be able to "see", which Application Signature the packages are contains?

 

Thanx for any thoughts on this...

    1 reply

    boneyard
    Valued Contributor
    December 7, 2019

    how exactly can only Fortinet say, but i can think of some ways.

     

    application control doesnt only check certificate CNs, but use more things like ports, IPs, ...

     

    but even when looking at the CN it is probably different between both those two, your browser goes to web.whatsapp.com but your phone with probably go to somethingelse.whatsapp.com

     

    there might be different servers that handle web and phones, so destination IPs can be used.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.