Skip to main content
Adam19892000
New Member
March 7, 2022
Question

Guest Devices certificate error via Web Filtering

  • March 7, 2022
  • 1 reply
  • 13581 views

Hi, 

 

Would someone be able to advise how to allow guest devices to use the web filtering without there being SSL inspection? I am unable to add any certificate onto the device but would like webpages to be blocked based on the web filtering policies. At the moment, the firewall is showing its certificate so the device doesn't trust the local certificate so brings an error before the web filtering block page is shown. 

 

I am utilising a separate VDOM for the guest system so it doesn't interfere with Internal use where we would utilise a trusted certificate for web filtering but unfortunately not possible in this case. 

 

I didn't have an issue with this on version 6.2.5 but having the issue on 6.4.6. 

 

Any help would be greatly appreciated. 

 

Adam

1 reply

naibaho
Visitor III
March 7, 2022

Hi Adam19892000,

Maybe you can modify your SSL Inspection profile to allow Untrusted SSL certificates. Although, it is not good thing to do.

 

naibaho_0-1646665497978.png

Adam19892000
New Member
March 7, 2022

Hi, 

 

I've attached my current configuration via the GUI. The issue seems to be that the FortiGate replaces the site certificate with its own when going to a blocked page. So if I press continue it goes to the block page but then it seems to allow the block website from then on. I know I can't do deep packet inspection with Guest devices but that's not my intention. I just want basic web filtering available without the FortiGate interfering with its own local certificate. 

 

Guest SSL Inspection.PNG

Thanks

Adam

naibaho
Visitor III
March 7, 2022

Hi,

If you do not care with ssl inspection at all, you can modify your ssl profile to allow all certificate signiture, include Blocked certificate, Untrusted and Invalid.