Skip to main content
Chris
New Member
January 3, 2016
Solved

Problem with SSl deep-Inspection and Websites

  • January 3, 2016
  • 1 reply
  • 26387 views

Hi, at first a happy new year to all. I have a Problem when i enable ssl deep-Inspection and surfing through the Web. I noticed that some sites loading only if i reload the site twice. Sometimes but not often I get a "ssl_error_bad_mac_read" error in Firefox. It also went gone when I reload the site. It is relative often reproducible when I am surfing through the fortinet forum. I am using the build in fortinet proxy certificate which CA is certainly imported in the browser under trusted ca authorities I have checked this with some other browsers and on other machines to rule out that it is a browser/machine problem only. The goal why i have enabled deep inspection is to use antivirus in https. Allow Invalid SSL Certificates and Log Invalid Certificates are both enabled but I get no errors. Like I said it is not on all sites but when I noticed that and loading process was too long then I reload the site and now it comes up. Then I figured out when deep-inspection is turned off then all runs well. How can I check what happens. Sniffing the traffic gave no usefull hints until now. I see sometimes only the req but no ack. Any hints for cli commands that can help to encircle the problem more precisely? My device is a FGT 60D with V5.2.5 Any help is appreciated.

Best answer by Willem_Bargeman

We have the same issue. Working with support on this case.

1 reply

emnoc
New Member
January 4, 2016

What I would do;

 

1:Isolate a fw-policy with ssl deep-inspection for one site only

 

2:Run the diag debug app ssl -1 command review the output

 

3:test using various  browser

 

I can't give you a exact reason for your problem but does it happen with fire-fox, ie and chrome? to the same site ? Chrome seems to exhibit issues that's not seen n IE or  Safari or FFOX. It also has better support and security and support SHA256 right out the box.

 

 

Chris
ChrisAuthor
New Member
January 4, 2016

Hi emnoc,

 

thanks for the hints.

 

I have enabled deep inspection an runs the debug but I see nothing.

There is no application ssl but only sslvpn which is surely not what we need i think.

 

 

emnoc
New Member
January 4, 2016

Did you run diag debug flow and against the site(s)?

 I'm sure that will probably give you some more details.