Skip to main content
mperez
New Member
May 13, 2019
Question

Block https sites whitout ssl inspection

  • May 13, 2019
  • 1 reply
  • 4456 views

Hi!

We want to block the https pages but for this you need to activate ssl inspection option

At this moment we have it configured in this way:

 

And a web filter with manual URLs filter(like *netflix*) but the https websites are not blocked

Do you know how I can block https sites whitout ssl inspection ? We use v 6.04

 

Thanks! 

    1 reply

    Iescudero
    New Member
    May 28, 2019

    Hello!

    You can block the port TCP 443 specifically, which is the default for HTTPS.

    it's better that you block all ports including 443 and only enable that you will use.

     

    Bye!

     

    emnoc
    New Member
    May 28, 2019

    You block by SNI and no you do not need to  do full-ssl-inspection

    https://kb.fortinet.com/kb/documentLink.do?externalID=FD34661