Skip to main content
Jirka1
Explorer II
November 15, 2017
Question

SSL inspection leads me to madness ...

  • November 15, 2017
  • 4 replies
  • 7560 views

Hello, are you experiencing a problem with detecting and viewing Cloud Apps in version 5.6.x (specifically 5.6.2)? We have a deep ssl inspection set up, Fortinet_CA_SSL certificateimported to all PC,and an application control set (all applications monitoring). I tried lots of cloud applications (FB, Twitter, Dropbox, Instagram, Office365, Gmail and others). I then looked into Fortiview-> Cloud App and there were only GoogleSearch and Dropbox and instead of the email address in the CloudUser section there is only an IP address What is wrong? On another box (v5.4.6) it looks fine (also a few applications are not displayed, but not as large as 5.6.2).

 edit "__upg_deep-inspection"
        set comment "Deep inspection."
        config ssl
            set inspect-all deep-inspection
            set allow-invalid-server-cert enable
        end
        config https
        end
        config ftps
        end
        config imaps
        end
        config pop3s
        end
        config smtps
        end
        config ssh
            set ports 22
            set status disable
        end
        config ssl-exempt
            edit 1
                set type address
                set address "xxxxx"
            next
            edit 2
                set type address
                set address "xxxxx"
            next
            edit 3
                set type address
                set address "xxxxx"
            next
            edit 4
                set fortiguard-category 31
            next
        end
        set caname "Fortinet_CA_SSLProxy"
        set ssl-exemptions-log enable

edit 35
        set uuid 1c7893e4-c8a0-51e7-66bc-7337d7a0d788
        set srcintf "ssl.root"
        set dstintf "wan1"
        set srcaddr "xxxxxL_range"
        set dstaddr "all"
        set action accept
        set schedule "always"
        set service "ALL"
        set utm-status enable
        set logtraffic all
        set users "xxxxx"
        set tcp-mss-sender 1354
        set tcp-mss-receiver 1354
        set comments "Clone of 32"
        set av-profile "default"
        set webfilter-profile "VPN"
        set ips-sensor "protect_client"
        set application-list "TEST"
        set profile-protocol-options "default"
        set ssl-ssh-profile "__upg_deep-inspection"
        set nat enable

 

Thanks Jirka

4 replies

packetpusher
New Member
November 16, 2017

Did you find any resolution?

 

Thanks

Jirka1
Jirka1Author
Explorer II
November 16, 2017

No. I will wait few days if someone kick me an idea. If not, I will create ticket to support. Jirka

packetpusher
New Member
November 17, 2017

It sounds like a bug to me I would report it to Fortinet TAC.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.