Skip to main content
aymericQA
New Member
June 23, 2025
Question

SSL Inspection -> systematic SSL Error server-rst

  • June 23, 2025
  • 1 reply
  • 779 views

Hello everyone

 

After a series of upgrade from fortiOS 5.6 to 7.4.8 on a FG101 cluster, i can't enable SSL Inspection anymore.

 

Every policy where i have SSL Inspection + (Web filter or Application control), web pages end up with a 'ERR_CONNECTION_RESET' in the browser and a SSL Error is logged 

 

forti.png

 

 

If a choose a 'non-inspection' profile, no issue.

If I disable 'Server certificate SNI check' in a non working SSL profile, the error is gone too.

 

Any advice or experience ?

 

Thank you

Aymeric

1 reply

ebrlima
Staff
Staff
June 23, 2025

FortiOS enhanced it's TLS support from 5.6 to 7.4, so SNI check is probably the cause of the issue. Check SSL logs for errors in SNI validation and take a look at the behavior when each of the actions is defined on the ssl inspection profile:

 

Screenshot 2025-06-23 172610.png