Firewall decisions based on SNI field?
Hi all,
Does anybody know if FortiGate can be configured to do this?
[ul]Today, when virtually any TLS client supports the SNI field, this would be very useful feature.
Thanks,
Vladimir.
Hi all,
Does anybody know if FortiGate can be configured to do this?
[ul]Today, when virtually any TLS client supports the SNI field, this would be very useful feature.
Thanks,
Vladimir.
FortiGate should look at the SNI by default for webfiltering according to this article:
https://kb.fortinet.com/k....do?externalID=FD34661
your feature to use it in the ipv4 policy is sort of using a webfilter profile with fixed entries in my opinion. but to have it happen automatically is not something how the fortigate operates on layer 4.
the question to keep in mind is how long this be useful, SNI is close to getting encrypted, once that happens the feature becomes useless.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.