Skip to main content
Ydaew
New Member
July 16, 2019
Solved

SSL Decription

  • July 16, 2019
  • 1 reply
  • 2503 views

Hello, 

I'm using FortiGate to decrypt web server traffic, how to know if the traffic is really decrypted from the FortiGate log itself ?

    Best answer by emnoc

    You can monitor the logs and look at that fwpolicyid. A sure way is to inspect the client\server-hello. If you see the MiTM  forced certificate in the https lock in the browser, than you know a device was in the middle. Review the following 

     

    http://socpuppet.blogspot.com/2017/11/ssl-state-cache-msie.html

     

    The left screenshot is a proxy doing MiTM and the right is the correct ca-chain. https://crt.sh/ is a good tool to know the proper cert issuer details btw.

     

    e.g ( to see all cert listed for example.com ) 

     

    https://crt.sh/?q=%25.example.com

     

    Ken Felix

    1 reply

    emnoc
    emnocAnswer
    New Member
    July 16, 2019

    You can monitor the logs and look at that fwpolicyid. A sure way is to inspect the client\server-hello. If you see the MiTM  forced certificate in the https lock in the browser, than you know a device was in the middle. Review the following 

     

    http://socpuppet.blogspot.com/2017/11/ssl-state-cache-msie.html

     

    The left screenshot is a proxy doing MiTM and the right is the correct ca-chain. https://crt.sh/ is a good tool to know the proper cert issuer details btw.

     

    e.g ( to see all cert listed for example.com ) 

     

    https://crt.sh/?q=%25.example.com

     

    Ken Felix

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!