Skip to main content
MohammedAlrawi
Visitor III
February 25, 2025
Question

SSL inspection on inbound traffic

  • February 25, 2025
  • 1 reply
  • 1780 views

Hi,

 

I have been given a task to activate the SSL Certificate inspection (not full) on the inbound traffic (on published servers lets say) so I tried to search for almost one week but couldn't get anything on the inbound traffic SSL inspection I have some questions if you can help me with that I would really appreciate it :

1-What is the difference between Full inspection and SSL Certificate inspection and which one would be best practice? as am trying to test out some stuff on the published test server.

2-What is the best practice for SSL Certificate and just to give you more information we user VIP as I found the some information it says that the traffic would be decrypted when coming to the firewall and traffic would be inspected then rencrypted the question here is which CA do I use in the certificate option ? 
3-anything related links sources would be really appreciated for more info on the inbound SSL Certificate inspection as I tried to search found little info I know am doing something wrong here for searching but my English isn't my first language and am still in my first year in networking.

 

Many thanks in advance.

1 reply

AEK
SuperUser
SuperUser
February 25, 2025

Hi Mohamed

Here is for inbound traffic when you have a published server (I suppose it is for a Web server):

  1. Certificate inspection only inspect the SSL certificate (validity, expiration, CA, ...)n while deep inspection decrypt the traffic (for content analysis) then re-encrypt it again (if needed, that's why here VS is better than VIP). Certificate inspection will not help you in anything here, unless you have a WAF behind the firewall (I mean dedicated WAF, not FortiGate's embedded WAF). If you have a dedicated WAF then you don't need deep inspection at FG level since the WAF is application firewall ideal for HTTP inspection
  2. For public server you will need a certificate signed by public CA. If this for private usage then you just need it from your Corp's private CA
  3. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-configuration-for-HTTPS-Virtual-Server/ta-p/225289

Hope it helps

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!