FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nkojha
Staff
Staff
Article Id 196360

Description

 

This article describes how to configure the SSL/SSH Inspection profile to inspect traffic on all ports.
By default, the deep-inspection profile will not inspect all ports, and some traffic might not be inspected completely.

Scope

 

FortiGate v7.0+.

Solution

 

  1. Clone the deep-inspection profile. Under Security Profiles -> SSL/SSH Inspection, 'right-click' on deep-inspection and select 'Clone'. Provide a new name, for example 'Clone of deep-inspection', and select OK to save. 

Screenshot 2025-12-03 153454.png

 

  1. Edit the 'Clone of deep-inspection' profile, enable 'Inspect All Ports', and select OK.
 
Screenshot 2025-12-03 153958.png

 

  1. Under Policy & Objects -> Firewall Policy, select the corresponding firewall policy and select 'Edit'. Change 'SSL Inspection' to 'Clone of deep-inspection' and select OK to save. 

Screenshot 2025-12-03 154343.png

 

To enable 'Inspect All Ports' in the CLI: 

 

config firewall ssl-ssh-profile

    edit "Clone of deep-inspection"

        config ssl

            set inspect-all deep-inspection
        end

    next

end