FortiGate's option "Inspect All Ports" affect traffic
Hello!
Anybody knows how "Inspect All Ports" option in SSL/SSH-inspection profile works? I didn't find detailed information about this option. When I turn off "Inspect All Ports" FortiGate lose about 200K sessions from CDN (Content Delivery Network) for 2 of 10 web-applications. CDN download static content via this sessions. Users start to get 5xx error when try to open web-application, but on FortiGate I don't see drops in logs or sessions reset in the traffic dump. When I turn on "Inspect All Ports" again sessions is back and all web-applications work fine. Looks like FortiGate can't process that amount session by internal proxy. I have FortiOS 7.0.6 and proxy-mode for all policies.
