Created on
06-19-2022
09:49 PM
Edited on
06-18-2025
05:36 AM
By
Jean-Philippe_P
This article describes two methods that can be used when ssl-deep-inspection and proxy-based inspection is used on a very general firewall policy (source: Any destination: Any) and traffic to a specific website is blocked because of it.
Ensure FortiOS v6.2.2 and above is used. The goal is to allow access to specific websites whilst 'bypassing' the firewall policy which has ssl-deep-inspection and proxy-based inspection.
Only traffic to the specified website in this firewall policy will be allowed.
Method 1: (Exempt from SSL Inspection)
diagnose firewall fqdn list | grep twitter
For v7.0 and later:
diagnose firewall fqdn list-all | grep twitter
diagnose firewall fqdn list | grep <configured_website_name>
For v7.0 and later:
diagnose firewall fqdn list-all | grep <configured_website_name>
Method 2 (Create another policy without deep-inspection and proxy-based enabled to allow the traffic):
Ensure the newly created FQDN firewall policy is placed on top of the existing firewall policy in the firewall policy sequence.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.