Source IP for cert probe
Hi FGT admins
FortiOS 7.4.12. All HTTPS sited are blocked with error: “SSL connection is blocked due to unable to retrieve server's certificate”.
In the latest FOS updates the FGT probes the certificate itself (self generated traffic) before allowing or denying the traffic, right.
I checked this tech tip and I know we can change cert-probe-failure as workaround.
But I my case I know the issue is caused by my WAN interface having one primary private IP and one public IP as secondary IP (ISP constraint). I had to change source-ip for many services like DNS and FortiGuard in order to make them reachable. But can’t find similar source-ip for certificate probe traffic.
I know one other workaround is to make public IP primary and private IP secondary but I prefer avoid this change in case there is “source-ip” customization for cert probe.
Any useful info would be appreciated.
