Skip to main content
Gestinfo
New Member
April 10, 2019
Question

Problem HSTS Webfiltering

  • April 10, 2019
  • 1 reply
  • 4686 views

Hello !

 

I've searched an answer to my problem on the forum but didnt found it so i'm posting my own.

 

My problem is when a computer try to access a webpage which is blocked (e.g. facebook) i have not the Fortiguard who says "Web page blocked!" but an error who says "HSTS problem, someone might be trying to usurp the site. You will not have to continue etc..."

 

It is only working on IE, coz i guess he didnt have the HSTS check.

 

I understand that the problem is the fortigate is doing a MITM and so the browser see a wrong CA and so put a warning.

 

But someone know what can i do to get around that ?

 

 

Thanks a lot !

    1 reply

    kphed
    New Member
    September 26, 2019

    Check to see if "set https-replacementmsg" is set to enable or disable within the web filter profile (only present in the CLi and should be at the top before the Fortiguard categories). Depending on what it is set to will determine next course of action...I'll advise further if you reply to this post.