Skip to main content
Akmostafa
Explorer
January 15, 2026
Question

SSL certificate active probing

  • January 15, 2026
  • 3 replies
  • 466 views

Hello team,

What is the benefit of the active probing feature while Fortigae can just wait for the server certificate in response to the original client hello.

What is the need of actively probe the certificate in a new connection originating from Fortigate?

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-FortiGate-does-TLS-Active-Probe/ta-p/393239

 

3 replies

Akmostafa
AkmostafaAuthor
Explorer
January 15, 2026

I have thought awhile about it.

I expect that this is due the fact that I recent TLS versions the server certificate is sent encrypted. Hence in flow based certificate inspection policies Fortigate should not have visibility on the certificate. 

 

Thus, the feature should not be required in either proxy or deep inspection deployments.

AEK
SuperUser
SuperUser
January 15, 2026

In TLS 1.3 the certificate is sent encrypted.

But for 1.2 and below I think one other reason is that the cert inspection may be time consuming. So cert active probing can enhance user experience.

AEK
Akmostafa
AkmostafaAuthor
Explorer
January 15, 2026

I don't believe it would be any faster because fortigae has to start a new tcp connection and initiate TLS with the server to probe the certificate. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!