Skip to main content
burhanafridi603
New Member
August 2, 2022
Question

SSL Deep Inspection create Internet issue for Smartphones.

  • August 2, 2022
  • 3 replies
  • 13158 views

Hello Everyone

I am using fortigate 60F Firewall and i have enables SSL Deep packet inspection i have installed certificate on almost all devices, however , Smartphone devices giving internet access as soon as I activate any security profile such antivirus, ips etc.

I even installed Certificate on mobile devices but still an issue.

3 replies

Markus_M
Staff & Editor
Staff & Editor
August 2, 2022

Hi Burhan,

 

deep inspection (DPI) generally is difficult with unmanaged clients like BYOD devices, smartphones, often are.

You may be able to check with an Android app "pcapdroid" to create a packet capture per app when you get this displayed. It could be that your FortiGate is not sending the intermediate CA certificate that you might have/need and the client needs this.

To verify a certificate the client will also need to complete a chain of certificates.

Server certificate > intermediate certificate(s) > Root CA

A pcap will show this easier (if the TLS version is 1.2 or lower).

Quick idea is, if you have the intermediate, install it on the FortiGate certificate/CA store and FortiGate should automatically send it.

 

Even though I have seen the Androids causing trouble with this, but there is a good change I might not have it done right in the past.

 

Best regards,

 

Markus

 

 

burhanafridi603
New Member
August 3, 2022

Thanks Markus_M for your response.

 

I have installed only Fortinet_CA_SSL Certificate on all my devices, which I have downloaded from SSL/SSH Inspection Profile as shown in attached image.

 

The same certificate I have installed on laptop and Desktop as well as Android devices.

Please tell If i am wrong or do i have to download any other certificate from Fortinet firewall.


Also I will try with pcapdroid 

 

SSL Certificate.jpg

 

Markus_M
Staff & Editor
Staff & Editor
August 12, 2022

Hi Burhan,

 

yes, that certificate is correct. Needs to be installed on the client's trusted root cert store.

What exact(!) error does your browser give you when you get warnings?

 

Best regards,

 

Markus

sjoshi
Staff
Staff
August 2, 2022

Dear burhanafridi603,

 

Thank you for posting to the Fortinet Community Forum.

 

Problem Description:-
SSL Deep Inspection create Internet issue for Smartphones.

As per your description you are facing internet issue for smartphone if you enable deep inspection in the policy

Please confirm whether you have install the deep inspection certificate and its CA cert in the smart phones
Are you facing issue with windows PC in the same subnet?
Please share the policy configuration.
Also can you share the snapshot of the error you are getting in your smartphones. Is the issue for all smartphones or only few users

 

Let us know if this helps.

Thanks

Thanks, Salon
burhanafridi603
New Member
August 3, 2022

1) Please confirm whether you have install the deep inspection certificate and its CA cert in the smart phones.....

I have only installed Fortinet_CA_SSL certificate on all my devices as shown in the picture below.

 

2) Are you facing issue with windows PC in the same subnet?...

No PC's are working fine no issue.

 

3) Also can you share the snapshot of the error you are getting in your smartphones. Is the issue for all smartphones or only few users....

 

All smartphone users facing the same issue 

 

SSL Certficate installedSSL Certficate installedPolicyPolicypolicy 2.jpg

Markus_M
Staff & Editor
Staff & Editor
August 4, 2022

Hello Burhan,

 

you can try to create a new DPI profile, not use the read only default one.

Important will be the pcap and the exact error from the client (screenshot of link, if possible and the error on screen). Could be different that what I expect (unknown CA) and depending on that better ideas can be phrased.

 

Best regards,

 

Markus

Mangustos
New Member
November 29, 2022

There are a few things that could be causing this issue. It could be that the certificate is not installed correctly on the smartphones or that the FortiGate is not configured correctly for SSL deep packet inspection. If you have not already, I would recommend checking Fortigate's SSL deep packet inspection documentation to see if there are any specific settings that need to be configured. If the problem persists, I would recommend installing Motorola bug2go, which will scan your smartphone to find any bugs. In this way, you can find the problem. You can read an article about it at https://multitechverse.com/. Good luck!