Skip to main content
Jond
New Member
November 29, 2024
Question

"It looks like xyz.com closed the connection" with SSL Deep inspection enabled

  • November 29, 2024
  • 5 replies
  • 3349 views

Hi All,

 


I'm getting a lot of help desk tickets with stuff like "It looks like mathsbot.com closed the connection" (one of many sites!)  I use deep packet inspection.

 

I've tried pretty much every option on the profile to change that, but the only thing that seems to work is adding the site (or the relevant category) to the SSL exceptions.  I'm getting enough of these tickets for it not to be sustainable.

 

Any ideas anyone? (I do need DPI, educational institutions)


Cheers


Jon

#fortigate

5 replies

AEK
SuperUser
SuperUser
November 29, 2024

Hi Jon

Which FortiOS version?

AEK
Jond
JondAuthor
New Member
December 2, 2024

Hi there,

 

v7.2.8 build1639

 

Cheers

 

Jon

kaurm
Staff
Staff
November 29, 2024

Hello Jon,
What is the inspection mode used on the policy , please provide complete screenshot of the error.

Thanks

Jond
JondAuthor
New Member
December 2, 2024

Inspection mode is Proxy.

 

The error message is exactly what I put - "It looks like xyz.com closed the connection" (with a Edge graphic or similar)

 

Cheers


Jon

sjoshi
Staff
Staff
November 30, 2024

To address the issue of frequent help desk tickets related to sites like "mathsbot.com" closing the connection despite using deep packet inspection, consider creating a custom SSL/TLS inspection profile where you selectively exempt specific categories or websites prone to such issues, ensuring a balance between security and usability for educational institutions. This approach can help reduce the number of tickets while maintaining the necessary level of security.

Thanks, Salon
Jond
JondAuthor
New Member
December 2, 2024

Thanks Salon Raj Joshi

 

I'm getting this too frequently to do it for every site or category.  I'll end up exempting all the sites that I'm wanting to look at from a DPI perspective.

sjoshi
Staff
Staff
December 2, 2024

any specific error you are getting in SSL event logs on FGT

Thanks, Salon
callmeahero
New Member
November 30, 2024

SSL Deep Inspection can break certain websites, especially if they use non-standard SSL/TLS configurations.

 

The DPI feature inspects and re-encrypts traffic, which some sites might not support, causing the connection to fail.

 

While adding sites or categories to the SSL exceptions list works, it’s not ideal if you have a lot of sites.

 

However, exceptions might be necessary for websites that don’t work well with DPI.

 

Instead of adding many sites to exceptions, consider creating custom DPI profiles that allow more flexibility.

 

For example, you can disable certain checks like SSL certificate validation for specific sites or only apply DPI to certain traffic types.

 

If the issues are widespread and affecting many users, you might also want to check the SSL Forward Proxy settings.

 

This can help reduce issues with SSL decryption by managing the way certificates are handled.

 

You can review the logs to identify which sites or categories are causing the most issues.

 

Based on this, you might be able to fine-tune DPI settings to avoid interruptions.

AEK
SuperUser
SuperUser
December 2, 2024

Can you share the cli config of the related ssl inspection profile?

AEK
Jond
JondAuthor
New Member
December 2, 2024

FGT_601E_FW1 # config firewall ssl-ssh-profile

FGT_601E_FW1 (ssl-ssh-profile) # edit "Modded deep-inspection"

FGT_601E_FW1 (Modded deep-insp~ion) # show
config firewall ssl-ssh-profile
edit "Modded deep-inspection"
config https
set ports 443
set status deep-inspection
set unsupported-ssl-version allow
set expired-server-cert allow
end
config ftps
set status disable
set expired-server-cert allow
end
config imaps
set status disable
set expired-server-cert allow
end
config pop3s
set status disable
set expired-server-cert allow
end
config smtps
set status disable
set expired-server-cert allow
end
config ssh
set ports 22
set status disable
end
config dot
set status disable
set unsupported-ssl-version allow
set expired-server-cert allow
end
set allowlist enable
config ssl-exempt
edit 1
set type address
set address "*.autodesk.com"
next
edit 2
set type address
set address "*.autodesk360.com"
next
edit 3
set type address
set address "*.castle.eu.com"
next
edit 4
set type address
set address "*.cdninstagram.com"
next
edit 5
set type address
set address "*.cricut.com"
next
edit 6
set type address
set address "*.engweld.co.uk"
next
edit 7
set type address
set address "*.fab.com"
next
edit 8
set type address
set address "*.facebook.com"
next
edit 9
set type address
set address "*.facebook.net"
next
edit 10
set type address
set address "*.fbcdn.net"
next
edit 11
set type address
set address "*.instagram.com"
next
edit 12
set type address
set address "*.psiexams.com"
next
edit 13
set type address
set address "*.psionline.com"
next
edit 14
set type address
set address "*.pubnubapi.com"
next
edit 15
set type address
set address "*.sky.com"
next
edit 16
set type address
set address "*.wpmeducation.com"
next
edit 17
set type address
set address "Alphabet"
next
edit 18
set type address
set address "api-uk.quadient.com"
next
edit 19
set type address
set address "catalogue.chigroup.ac.uk"
next
edit 20
set type address
set address "employerhub.hants.gov.uk"
next
edit 21
set type address
set address "farrier-reg.gov.uk"
next
edit 22
set type address
set address "idp.lrs.education.gov.uk"
next
edit 23
set type address
set address "jusp.jisc.ac.uk"
next
edit 24
set type address
set address "meet.turns.goog"
next
edit 25
set type address
set address "seas.org.uk"
next
edit 26
set type address
set address "socket-io.quadient.com"
next
edit 27
set type address
set address "southofenglandeventcentre.co.uk"
next
edit 28
set type address
set address "workspace.turns.goog"
next
edit 29
set type address
set address "WPM_paymentgateway.wpm.flywire.com"
next
edit 30
set type address
set address "WPM_store.wpm.flywire.com"
next
edit 31
set type address
set address "www.coolmathgames.com"
next
edit 32
set type address
set address "www.cpdstore.ac.uk"
next
edit 33
set type address
set address "Outgoing External Hosts ALL PROTOCOLS ALLOWED"
next
edit 34
set type wildcard-fqdn
set wildcard-fqdn "*.alphabet.com"
next
edit 35
set type wildcard-fqdn
set wildcard-fqdn "*.animationuk.org"
next
edit 36
set type wildcard-fqdn
set wildcard-fqdn "*.chigroup.ac.uk"
next
edit 37
set type wildcard-fqdn
set wildcard-fqdn "*.giftround.co.uk"
next
edit 38
set type wildcard-fqdn
set wildcard-fqdn "*.google.co.uk"
next
edit 39
set type wildcard-fqdn
set wildcard-fqdn "*.google.com"
next
edit 40
set type wildcard-fqdn
set wildcard-fqdn "*.gov.uk"
next
edit 41
set type wildcard-fqdn
set wildcard-fqdn "*.lsi.co.uk"
next
edit 42
set type wildcard-fqdn
set wildcard-fqdn "*.texthelp.com"
next
edit 43
set type wildcard-fqdn
set wildcard-fqdn "*.xams.co.uk"
next
edit 44
set type wildcard-fqdn
set wildcard-fqdn "*.youtube.co.uk"
next
edit 45
set type wildcard-fqdn
set wildcard-fqdn "*.youtube.com"
next
edit 46
set type wildcard-fqdn
set wildcard-fqdn "aub.ac.uk"
next
edit 47
set type wildcard-fqdn
set wildcard-fqdn "google-drive"
next
edit 48
set type wildcard-fqdn
set wildcard-fqdn "google-play"
next
edit 49
set type wildcard-fqdn
set wildcard-fqdn "google-play2"
next
edit 50
set type wildcard-fqdn
set wildcard-fqdn "google-play3"
next
edit 51
set type wildcard-fqdn
set wildcard-fqdn "googleapis.com"
next
edit 52
set type wildcard-fqdn
set wildcard-fqdn "Questback"
next
edit 53
set type wildcard-fqdn
set wildcard-fqdn "ricoh.co.uk"
next
edit 54
set fortiguard-category 30
next
edit 55
set fortiguard-category 31
next
end
set ssl-exemption-log enable
next
end