Skip to main content
New Member
August 12, 2026
Question

TLS/SSL handshake logs with Certificate Inspection profile

  • August 12, 2026
  • 2 replies
  • 80 views

Hi everyone,

I’m trying to understand whether there is a way to log some TLS/SSL handshake information when using an SSL/SSH profile configured with Certificate Inspection, rather than Full/Deep Inspection.

I tested the following settings:

set ssl-handshake-log enable
set ssl-server-cert-log enable
set ssl-negotiation-log enable

but, from my tests, these logs seem to be generated only when the SSL/SSH profile is configured for Full/Deep Inspection.

What I would specifically like to retrieve, even when using Certificate Inspection, is information such as:

  • the SNI (Server Name Indication) sent by the client;
  • the negotiated TLS version;
  • ideally, other basic TLS handshake metadata that FortiGate can observe without decrypting the session.

Since SNI and TLS version are available during the handshake and do not necessarily require payload decryption, it would be very useful to have them available in the traffic/SSL logs also with Certificate Inspection.

Thanks in advance for any suggestions or clarification.

 

2 replies

sjoshi
Staff
Staff
August 13, 2026

Hi ​@leleargo 

 

ssl-handshake-log, ssl-server-cert-log, and ssl-negotiation-log are suppose to use with deep inspection.Full/Deep Inspection terminates the TLS session (FortiGate acts as a man-in-the-middle). Because it negotiates the handshake with both client and server
Certificate Inspection does not terminate the TLS session. It only inspects the headers up to the SSL/TLS layer and cannot negotiate with the server on the TLS version to use

https://docs.fortinet.com/document/fortigate/7.0.0/new-features/183724/enhance-tls-logging-7-0-1

Thanks, Salon
leleargoAuthor
New Member
August 13, 2026

Thanks, understood.

Is there any way to log information that FortiGate can passively read with Certificate Inspection, such as the client SNI from the TLS ClientHello?

I’m not looking for information negotiated by FortiGate, just TLS metadata that it already observes without decrypting or terminating the session.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!