Skip to main content
clarkg
New Member
October 16, 2014
Solved

https sites issues

  • October 16, 2014
  • 3 replies
  • 33626 views
So We updated our Firmware to 5.0.9 not too long ago and we now seem to have issues with https sites. I just need to know if this behavior is normal, or if there is something wrong. The issues we have are that some https sites, not all, when users access them, they will come up with any or all of the following..... A blank white page The will state that there is no Java, or Flash installed, when there is. Or that the incorrect java or flash version is installed, even when we know for 100% sure that the correct version is on the pc. I can do one of 2 things to fix this. 1. I can either create an address object with the site url in it, and put it into a policy in front of our main user policy, that ONLY has AV and IPS turned on. SSL inspection and webcache are turned off in this policy. 2. I can put the url into the url filter the user gets as a wildcard and exempt, and that also makes the site work. Again, on our previous version of firmware, which I BELIEVE was 5.0.6 we didn' t seem to see this issue very often. However under the 5.0.6 firmware we were also having multiple issues with the url filter engine and ips engine and I believe the sslworker daemon crashing all the time. The firmware we are on now, 5.0.9 we do not have those issues. So I just need to know if these issues we are seeing now with https sites are normal behavior until the url is exempted, or if something else is going on. I have a ticket open with fortinet, just wanted to get some
    Best answer by Fullmoon

    hope this help,got an issue with dropbox once ssl inspection was enabled in a policy.updated my version from 5.2.1 to 5.2.2 and do ssl exemptions. pls see attached file

    3 replies

    billp
    New Member
    October 16, 2014
    Clark, I can report some oddities with the SSL/SSH Inspection policy. If I inspect port 443, it will prevent my Skype clients from logging in. I posted about this earlier, but I seem to be alone with this problem based on the responses. You might try turning off your SSL/SSH Inspection policy to see if it fixes the problems you' re seeing. I am currently on firmware 5.0.7, but am considering jumping to 5.0.9 soon so that I have the benefit of the latest bug fixes. If you are using 5.0.6, you probably want to jump to at least 5.0.7 because of the heartbleed issues with earlier versions.
    clarkg
    clarkgAuthor
    New Member
    October 29, 2014

    I AM currently on 5.0.9 and having these issues.  Is it a good idea to downgrade to 5.0.7?  Turning off the ssl inspection seems to make the problems go away.  

     

    billp wrote:
    Clark, I can report some oddities with the SSL/SSH Inspection policy. If I inspect port 443, it will prevent my Skype clients from logging in. I posted about this earlier, but I seem to be alone with this problem based on the responses. You might try turning off your SSL/SSH Inspection policy to see if it fixes the problems you' re seeing. I am currently on firmware 5.0.7, but am considering jumping to 5.0.9 soon so that I have the benefit of the latest bug fixes. If you are using 5.0.6, you probably want to jump to at least 5.0.7 because of the heartbleed issues with earlier versions.

    Bromont_FTNT
    Staff
    Staff
    October 29, 2014

    With deep SSL inspection there are certain programs/apps which will not work. When visiting HTTPS websites with a browser you can either continue through the certificate warning or import the cert/CA into the browser... Programs like Skype are looking for specific client/server certificates so deep SSL inspection will never work with these.

    Phuoc_Ngo
    New Member
    October 29, 2014

    Full SSL inspection is still very shaky.  We are on 5.2.1 version and SSL inspect work for a certain vendors and doesn't work for other.  In our case, whenever we enable full SSL Inpsect, Microsoft Office365 mail stop connecting and LYNC, Gotomeeting,Webex group sharing stop work.  It work perfectly with only SSL certificate inspection but does not work with full SSL inspection. 

    Bromont_FTNT
    Staff
    Staff
    October 29, 2014

    As stated before it can't work for applications which require a specific certificate (certificate pinning)

    SteveRoadWarrior
    New Member
    May 15, 2015

    We just had to do something similar. 

     

    Found an easy fix which kept it working for the rest of the internet sites:

    - edit the web filter and enable web site filter

    - add *.dropbox.com to the URL exemption list (chose wildcard)

     

    see attached image

     

    This allows the regular dropbox SSL Cert to be used for that site, but everything else has to be processed by the Fortigate.

     

    Firmware is 5.0.11 - 80C