Skip to main content
AEK
SuperUser
SuperUser
July 13, 2026
Solved

Source IP for cert probe

  • July 13, 2026
  • 6 replies
  • 85 views

Hi FGT admins

FortiOS 7.4.12. All HTTPS sited are blocked with error: “SSL connection is blocked due to unable to retrieve server's certificate”.

In the latest FOS updates the FGT probes the certificate itself (self generated traffic) before allowing or denying the traffic, right.

I checked this tech tip and I know we can change cert-probe-failure as workaround.

But I my case I know the issue is caused by my WAN interface having one primary private IP and one public IP as secondary IP (ISP constraint). I had to change source-ip for many services like DNS and FortiGuard in order to make them reachable. But can’t find similar source-ip for certificate probe traffic.

I know one other workaround is to make public IP primary and private IP secondary but I prefer avoid this change in case there is “source-ip” customization for cert probe.

Any useful info would be appreciated.

Best answer by funkylicious

indeed it says about an ipsec example, but i think that you can test it also since it wont really ‘hurt’ anything and due to having a more unique scenario.

also i would also give this a try

 

6 replies

funkylicious
SuperUser
SuperUser
July 13, 2026

try 

 

"jack of all trades, master of none"
AEK
SuperUser
AEKAuthor
SuperUser
July 13, 2026

Thanks Funkylicious for your feedback.

It seems this is IPsec related, right? If so then this is not really what I’m looking for.

AEK
funkylicious
SuperUser
SuperUser
July 13, 2026

indeed it says about an ipsec example, but i think that you can test it also since it wont really ‘hurt’ anything and due to having a more unique scenario.

also i would also give this a try

 

"jack of all trades, master of none"
sjoshi
Staff
Staff
July 14, 2026

Hi ​@AEK 

 

Have you tried below changes.

config ips global

    config tls-active-probe

set source-ip  (set public IP here)

end

end

 

did it worked? 

Also can you confirm if any of the policy are in proxy mode where certificate inspection is enabled?

Thanks, Salon
AEK
SuperUser
AEKAuthor
SuperUser
July 14, 2026

Thank you ​@funkylicious and ​@sjoshi ,

I’ll try each method and let you know.

AEK
AEK
SuperUser
AEKAuthor
SuperUser
July 14, 2026

Thanks to both. That was the right fix.

Ps: It seems we cannot mark more than one response as “Best answer”, so I mark the first one provided by Funkylicious.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!