Skip to main content
Geert_m
New Member
April 3, 2024
Question

Configuring security profiles Fortigate

  • April 3, 2024
  • 2 replies
  • 6394 views

Hello,

I am planning to configure security profiles in some of the firewall policies that are on my FortiGate. My question about this is, if I need a valid/signed certificate installed on Fortigate and my hosts to inspect all traffic passing the FortiGate in order to inspect all data from packets and block certain traffic because it contains malware etc?

 

How does this work, can someone explain me?

Kind regards,

 

 Geert

2 replies

ozkanaltas
Valued Contributor III
April 3, 2024

Hello @Geert_m ,

 

As you know at present almost all internet traffics are using SSL. Because of that Fortigate doesn't inspect these traffics without ssl-inspection. 

 

You don't need the signed certificate for ssl-inspection. You can create one CA certificate via your AD, OpenSSL or you can use the default Fortigate CA certificate. But if you use not signed certificate you need to deploy this certificate to your client's computer certificate store for your client's comfort. 

 

if you have a more question about SSL inspection, you can ask without hesitation.

 

Also, you can review these articles about ssl-deep inspection. 

 

https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/605938/why-you-should-use-ssl-inspection

 

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/122078/deep-inspection

 

Geert_m
Geert_mAuthor
New Member
April 4, 2024

I configured a firewall policy that has web filtering enabled. When adding the web filtering security profile, I need to enable SSL inspection as well in the new firewall policy. So I enabled this and added the CA Certificate to my webbrowser its trust-chain.

CA.pngerror.png

But when I try to access Facebook, I get the warning above.

 

What am I doing wrong here?

ozkanaltas
Valued Contributor III
April 4, 2024

Hello @Geert_m ,

 

Can you try to import the certificate to the Windows certificate store? After that, you need to do one more thing for Firefox (another browser does not need this setting). 

 

Windows Enterprise Support Starting with version 49, Firefox can be configured to automatically search for and import CAs that have been added to the Windows certificate store by a user or administrator.  Type about:config in the address bar and press Return. A warning page may appear. Click Accept the Risk and Continue to go to the about:config page. Search for the security.enterprise_roots.enabled preference. Click the Toggle Fx71aboutconfig-ToggleButton button next to this preference to change its value to true. Restart Firefox.

 

 

Also, you can review this document about how to install CA cert on a Windows system.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-import-a-FortiGate-nbsp-deep-SSL/ta-p/267932

 

hbac
Staff
Staff
April 3, 2024

Hi @Geert_m,

 

If you are planning to use deep inspection, you will need to install a trusted certificate to avoid certificate warning. Alternatively, you can import the FortiGate build-in certificate to the browser. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-deep-inspection-and-import-a/ta-p/196840

 

Regards,