Fortigate deep inspection certificate
Hi everyone!
I do have HQ, and 10 more branches. Each branch has direct internet. So I need to do a deep inspection at each site. I was using the normal way. Generate a CSR from each Firewall. Sign it by my Local CA as a subordinate. Then import it to my FortiGate. Then use this new cert in my SSL policy.
But I have read a document from Fortinet showing a better way to create on my Local CA:
Create a Microsoft sub CA certificate
Still, I'm confused. What's the different, and better way? Just generate one cert as mentioned. Or do CSR from each FW to let FW information appear to users when there is an SSL error?
Kindly advise and let me know the best and different.
Note. I do have Local CA and FortiManager to manage all my 10 FortiGates.
