Skip to main content
sforbus
New Member
August 13, 2019
Solved

ERR_SSL_PROTOCOL_ERROR on Google Chrome

  • August 13, 2019
  • 34 replies
  • 111804 views

We are having a bizarre problem since updating to 6.2.1 (we updated due to a memory leak issue in 6.2.0).

 

Certain sites are giving us a ERR_SSL_PROTOCOL_ERROR only in Google Chrome. I have tried all the usual troubleshooting for this error, but the only thing that fixes it is restarting the fortigate. Two sites (facebook.com and login.renweb.com) both use TLS 1.3, but we can get to facebook without a problem and we cannot get to the other site. After rebooting the device, it works for several days and then starts behaving poorly again.

 

Other browsers work fine, including Internet Explorer, Edge (not Chromium based) and Firefox.

 

I have attempted to disable SSL certificate inspection, but that does not seem to affect the problem one way or another. I also tried putting the fortigate back on its factory certificate.

 

My next step will be to revert to 6.0 branch, where I did not experience this issue, but I figured I would post first to see if anyone had similar experiences.

 

    Best answer by emnoc

    Have anybody used curl against theses sites? Inspect the certificate and if you see any stale cert clear them. You can also test in a incognito window and see if the problem exists.

     

    It sounds  like a browser issues. FWIW. I check all of those sites from  fortios v6.2.3 and see no issues using chrome on windows { Version 78.0.3904.87 (Official Build) (64-bit) }

     

    Ken Felix

    34 replies

    dxnet
    New Member
    August 20, 2019

    Firmware 6.2.1 I have similar error, cant open https://www.whatsapp.com/ in Google Chrome, in IE works.

    I add exempt for ssl inspection (wildcard *.whatsapp.com), but it doesn't work. whatsapp in chrome works only ssl deep inspection is disabled

    sforbus
    sforbusAuthor
    New Member
    August 20, 2019

    I have solved the problem by downgrading back to 6.0.5, I believe. It has been a couple of days and this problem has not resurfaced. I will see if it happens again.

    bbilut
    New Member
    August 20, 2019

    Have you tried disabling QUIC protocol in Chrome?

    kingD
    New Member
    August 30, 2019

    I configured an url filtering that works only with IE. Chroom lets all the https traffic pass

    marcrp
    New Member
    August 30, 2019

    We are experiencing the same issue too since upgrading to 6.2.1.

     

    Although for us it seems to be only affecting IE11 and we randomly get the error "Can’t connect securely to this page" "Turn on TLS 1.0, TLS 1.1, and TLS 1.2 in Advanced settings and try connecting to"

     

    The only work around is to create a rule with no AV inspection and put the site we are having issues with as the destination and it seems to work. 

     

    I think I will be reverting to 6.2.0 as I have so many random sites that aren't working for us.

     

     

    seadave
    New Member
    September 1, 2019

    TLS 1.3 is a different beast.  Can't tell from the bottom of this page if MiTM TLS 1.3 is only supported in Flow Based inspection or also in Proxy mode (which most people use).  You may need to change from proxy to flow.

     

    https://docs.fortinet.com/document/fortigate/6.2.0/new-features/35927/tls-1-3-support

     

    One other issue we ran into when doing major version upgrades is to ensure your CA cert used for MiTM is not using a weak signing algorithm such as SHA1.  Make sure you generate a self signed one that is at least 2048bits using SHA256 if RSA and 384bits if using ECDHE.

     

    We have found some domains that use HSTS (cert pining), those will not accept a connection that is broken by a proxy.  We had to create a rule to exempt such domains from filtering if they were legitimate for business.

     

    Finally, I wouldn't be using 6.2.X in production yet and I'd only use it on devices bigger than E series with a model number greater than 100.  Other models are prone to fault due to minimal RAM and CPU resources.  6.2 is still very new.  We are running 6.0.5 in production and it has proven to be very stable on 501Es

    GregAndo
    New Member
    September 3, 2019

    Things were going okay, but now we are beginning to see this too after having run for a few days.  I am not sure how far reaching it is, but, ironically, it is affecting my ability to log into the FortiGate web interfaces of my fleet, which are a mix of 6.0 and 6.2.1

     

    Has anyone been able to isolate the cause?  What about a temporary resolution that doesn't require a reboot?

    tracyb
    New Member
    September 3, 2019

    I just posted “Weak impersonation certificates blocking access to sites using ECC certificates”, then saw this post.  The two are possibly related.

    riyasander
    New Member
    October 3, 2019

    Mostly this error occurs due to the server issues and a lack of client authentication. There are some other reasons for ERR_SSL_PROTOCOL_ERROR on Google Chrome and you can fix this with https://www.clickssl.net/blog/fix-err_ssl_protocol_error-for-google-chrome this guide.

    mjcrevier
    New Member
    October 3, 2019

    You're running into a bug related to the SSL handshake & certificate-inspection profile when policy is set to proxy mode. Switch to flow-based inspection for now. Hoping this bug is fixed in 6.2.2.

    mp_na
    New Member
    October 10, 2019

    I've had similar issues since my rollup.

     

    All Chrome and Chromebooks broke.

     

    My resolution:

     

    I rebuilt all of the SSL inspection exemptions and web filter exemptions adding these links:

     

    https://support.google.com/chrome/a/answer/3504942?hl=en

    Jirka1
    Explorer II
    January 2, 2020

    Hello,

     

    i have the same problem on 6.2.3. I am unable to display the blocked https page correctly. In Chrome it ends with an "ERR_CONNECTION_RESET" error. HTTP queries work correctly. I have set up cert-inspection, flow policy and use only the FortiGuard category. In the profile configuration I tried to disable https redirect - set https-replacemsg disable, but I think the problem will be elsewhere.

     

    IE reports the error message: This page cannot be securely connected This may be because your site is using outdated or unsafe TLS security settings. If the problem recurs, try contacting the site owner.

     

    Has anyone solved this problem?

    Thanks. Jirka

    Jirka1
    Explorer II
    January 6, 2020

    Hello, anybody? Jirka

    nsumner36
    New Member
    September 1, 2021

    Have you tried going to 6.4.7? If this only effects Chrome my guess is it is related to QUIC, have you tried blocking QUIC?

    irvinborder
    New Member
    February 1, 2022

    When a browser shows the Err_ssl_protocol_error, it indicates the browser is no longer able to access or initiate the secured communication. There is no definite guide for managing this error. Follow given steps to resolve this error from Client side:

     

    • Try correcting the system date and time.
    • Try clearing Google Chrome browsing data.
    • Try clearing your SSL State.
    • Try disabling the QUIC Protocol.
    • Try checking your antivirus settings.
    • Try enabling all SSL/TLS versions.

    Also, this error is because of the following aerver side problems:

     

    • Invalid SSL or SSL is untrusted (self-signed)
    • SSL Not installed properly
    • Old Technology or SSL/TLS version for encryption
    Aayu
    New Member
    February 18, 2025

    The "ERR_SSL_PROTOCOL_ERROR" usually occurs due to an invalid SSL certificate or improper server configuration and also results from an SSL/TLS handshake failure. Try clearing your browser cache, checking your system date/time, disabling extensions, or using another browser. If the issue persists, check for expired certificates or server misconfigurations.

     

    There are different steps to fix this error. For a detailed guide, I found this helpful resource:-

    https://certera.com/blog/how-to-fix-err-ssl-protocol-error-in-chrome/.

     

    I hope this helps to fix the error!

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!