Skip to main content
Forti_Newbie
New Member
September 22, 2022
Question

FortiGate's option "Inspect All Ports" affect traffic

  • September 22, 2022
  • 8 replies
  • 3834 views

Hello!

Anybody knows how "Inspect All Ports" option in SSL/SSH-inspection profile works? I didn't find detailed information about this option. When I turn off "Inspect All Ports" FortiGate lose about 200K sessions from CDN (Content Delivery Network) for 2 of 10 web-applications. CDN download static content via this sessions. Users start to get 5xx error when try to open web-application, but on FortiGate I don't see drops in logs or sessions reset in the traffic dump. When I turn on "Inspect All Ports" again sessions is back and all web-applications work fine. Looks like FortiGate can't process that amount session by internal proxy. I have FortiOS 7.0.6 and proxy-mode for all policies.

8 replies

jintrah_FTNT
Staff
Staff
September 22, 2022

Hi,

What was the number of concurrent sessions on the device before changes? And what is the hardware model?

 

Best regards,

Jin

Forti_Newbie
New Member
September 26, 2022

Hi,

before changes the number of concurrent sessions was 300-400k concurrent sessions. After that about 50K. Hardware model is 1100E

jintrah_FTNT
Staff
Staff
September 26, 2022

Hi,

 

That hardware is much more capable FortiGate 1100E Series Data Sheet (fortinet.com)

So it appears the switching the modes are altering the traffic from flow to proxy mode, and the existing sessions could not be proxied from the middle of an ongoing session.

 

best regards,

Jin

Forti_Newbie
New Member
September 28, 2022

Yes, I think you're right. But where are this sessions? As I wrote before when I turn off "Inspect All Ports" FortiGate lose about 200K sessions from CDN and users start to get 5xx error when try to open web-application. It means that CDN try to create new sessions, but I don't see drops or other error on the FortiGate

jintrah_FTNT
Staff
Staff
September 28, 2022

Users are getting 5xx errors indicating there is no gateway connectivity upon attempts further. So if these sessions are still being initiated and logging of other types of traffic is enabled, we may see them in logs.  You may open a support ticket with config and sniffers for validation.

 

best regards,

jin

sferoz
Staff
Staff
September 29, 2022

Good Day,

Thank you for using the Community Forum. 

 

In addition to the above, you can check if there are any drops on the interface level. 

 

 #diag hardware deviceinfo nic 

or

#fnsysctl ifconfig portxx (xx port number)

 
Thanks,
Feroz

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!