SSL decryption causing TCP Reset
FG101F running 6.4.8 with full decryption turned on between domain endpoints and the WAN.
I can't figure out what if anything I'm doing wrong here. I have some sites - no common thread of certificate issuer that I can find - that cannot be accessed in modern browsers if SSL Full Decryption is enabled for that site. If I explicitly exempt a site, it loads. The client sees a timeout page after some time as if that site is down. The firewall log shows a TCP Reset by the client.
Happens in Firefox, Chrome, Edge, but the same sites load just fine in IE. So I assume it has something to do with the browser seeing the MITM and resetting?
The clients trust the SSL cert by internal CA and most sites work fine being inspected. Anyone know what might be going on?
I just started getting complaints about this last week, the sites were working before that.
