Skip to main content
Explorer
June 8, 2026
Question

SSL Inspection Blocking Network Acces

  • June 8, 2026
  • 3 replies
  • 199 views

After upgrading our FortiGate device from FortiOS version 7.6.6 to 7.6.7, users at the branch lost internet access when the BambiDeep SSL/SSH Inspection profile (Deep Inspection) was used in the firewall rule.

Traffic is allowed by the firewall rule, and NAT is working properly. However, HTTPS connections fail when Deep Inspection is enabled.

As a temporary solution, we changed the SSL/SSH Inspection profile from BambiDeep (Deep Inspection) to Certificate Inspection, and internet access was immediately restored.

 

 

The first rule includes certificate inspection, and internet access works fine, but the second rule is the old one and includes “BambiDeep” SSL inspection; after the firmware upgrade, internet access is not working. Also ı tested the problem on new rule by adding  BambiDeep SSL inspection ant internet acces is not working.

 

Are they any known issue about 7.6.7 version for tihs topic ?

3 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
June 12, 2026

Hello Dzhem35, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Regards,

Jean-Philippe - Fortinet Community Team
sjoshi
Staff
Staff
June 13, 2026

Hi ​@Dzhem35 

Can you confirm if the same Bambi Deep inspection certificate was used before the upgrade.

Do you see any SSL block logs?

Did you try installing the CA certificate on the endpoints.

Thanks, Salon
Dzhem35Author
Explorer
June 13, 2026

Hi ​@sjoshi, yes BambiDeep inspection certificate was using before without no problem, on friday 23:45 was auto uptaded the system to 7.6.6 to 7.6.7 after the upgrade this problem has seen

Also CA certificate already installed on the endpoints

sjoshi
Staff
Staff
June 13, 2026

Hi ​@Dzhem35 

Can you enable the Bambi deep inspection policy and bring it on top to reproduce the issue. Since it affects the user traffic please edit the source address to a specific endpoint IP so that only one user is affected and can test out.

Try accessing the websites and once the issue resurfaces check the SSL event logs.

Share the ssl event logs, if you see any block logs.

Thanks, Salon
jiahoong112
Staff
Staff
June 15, 2026

If you were to use deep-inspection without first installing the Fortinet_CA certificate that’s used for deep-inspection into the Trusted Root Certificate folder on your client device, your browser will not trust the Fortinet_CA certificate that is used to replace the website’s certificate. This is done so that deep-inspection can decrypt and inspect the full packet.

To fix this, you will need to install the certificate (Fortinet_CA) used for deep-inspection into the Trusted Root Certificate folder of your device.

 

https://docs.fortinet.com/document/fortigate/8.0.0/administration-guide/122078/deep-inspection