Skip to main content
Grom
New Member
March 29, 2018
Question

Exclude Lync (Skype for business) traffic from SSL deep inspection

  • March 29, 2018
  • 11 replies
  • 16811 views

Hi all.

We have a problem with Lync conferences, they are not working if inspection is on, if we exclude specific addresses from inspection, it works, but we want to exclude all Lync traffic, haw can I do it. We have Fortigate 100E.  

 

sorry for my English

    11 replies

    dmcquade
    New Member
    March 30, 2018

    Create Firewall Address objects for the URLs where the inspection is interferring. Add these objects to the exception list on your SSL Inspection profile. This is where wildcard FQDNs become very useful.

     

    hth

    d

    Grom
    GromAuthor
    New Member
    March 30, 2018

    That is the problem. My users have many meetings with a lot of different clients. And users very upset that they must to warn IT before each meeting. 

    Hosemacht
    Explorer
    March 30, 2018

    Hey there,

     

    just add a new willdcard fqdn adress with "*.lync.com" and add this to the exempt addresses in the refering ssl/ssh inspection Profile.

    This works for me.

     

    Regards

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!