Dns filter and redirect portal IP
In our DNS filter profile, we have checked the redirect checkbox and selected to fortiguard default for the ip.
So when a client asks for a blocked website, it'll get the IP of the fortiguard portal, like 208.91.112.55.
When the site is in SSL, then the browser will generate a warning that the name on the certificate don't match the one on the site and that's true.
For SSL inspection we already have a private root installed on all devices on our network. Would it be possible for the fortigate to generate a certificate on the fly for this site so the user facing the issue will know that it's blocked instead of calling support to know what to do with the warning ?
