Skip to main content
kamarale
New Member
March 20, 2025
Question

SSL inbound deep inspection

  • March 20, 2025
  • 4 replies
  • 1690 views

Hello,

I have these 2 doubts:

 

1- If I want to protect a web server NATed to internet , I can do this only with a normal VIP and SSL inspection , right?

I mean I do NOT need to enable Load Balance feature like this example:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-Inbound-SSL-Deep-Inspection/ta-p/191543

 

 

2- And if I want to protect for example an email server (encrypted traffic) in the SSL inspection profile ,under 

"Protocol Port Mapping" I have these 2 choices right:

   - select "Inspect all ports"

 or

 - on "HTTPS" add the ports that I want (i.e 25,587,465)

With any of these 2 I would be protecting my email server from malware and other attacks (with AV/IPS profiles) right?

 

Thank you in advace

Regards

 

 

 

 

4 replies

AEK
SuperUser
SuperUser
March 21, 2025

Hi Kamarale

  1. VS is somehow an advanced version of VIP and it offers more features, so I always use VS with deep inspection and WAF profile when I don't have dedicated WAF, and I always use VIP without deep inspection when I have dedicated WAF
  2. When you want to protect a mail server (25, 587 & 465) and you don't have a dedicated mail gateway, I think the right thing to do is to inspect all port, while in the firewall rule you allow ports 25, 587 & 465 (didn't test it but I think this will work for STARTTLS as well), and you will be able to protect against malware, spam and attacks
AEK
kamarale
kamaraleAuthor
New Member
March 21, 2025

Hello AEK, thank you for the reply.

Just to undestand it correctly. What would I gain if I use VS vs VIP if I am only protecting 1 web server (http/https)? I mean I am not interested in LB.

Normal VIP with inbound SSL inspection vs VirtualServer with inbound SSL inspection

 

Thank you

Regards

 

AEK
SuperUser
SuperUser
March 22, 2025

Hi Kamarale

Honestly when I protect Web servers with FGT's WAF I didn't try it with VIP, I always do it with VS, since this is the recommendation from Fortinet. I even don't know if it will fully work with VIP.

But at least with VS you can select SSL offloading mode (Client-FGT or Full), preserve client IP, redirect HTTP to HTTPS, and some HTTP header manipulation.

AEK
AEK
SuperUser
SuperUser
April 5, 2025
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!