FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
metz_FTNT
Staff
Staff
Article Id 247356
Description This article describes 'ssl-inspection' usage for URL Web filter.
Scope

FortiGate.

Solution

For plain text HTTP, traffic HTTP request is not encrypted.

Therefore 'ssl-inspection profile' is not mandatory and FortiGate can identify the full request URL http://example.com/index:

 

metz_FTNT_0-1677501314963.png

 

For HTTPS, however, the HTTP request is encrypted and it is usually the first application data packet from the client.

If only 'certificate-inspection' is used, the FortiGate cannot see the full request URL and can only identify the domain name in the SNI field of the client hello:

 

metz_FTNT_1-1677501599183.png

 

As shown in the picture, 'example.com' can be identified, but not the '/index' part.

Therefore in the case, for instance, to block:

'www.example.com/index" but allow "www.example.com/xxxx' this would not be possible.

It is only possible to apply rules based on the domain name but not URI.'