Created on
01-01-2015
12:45 PM
Edited on
04-14-2025
11:13 PM
By
Jean-Philippe_P
Description
This article demonstrates how to exempt certain destinations from Deep SSL inspection. Exempting an application/domain/website in the SSL-SSH profile means that FortiGate will trust that connection and will no longer apply security profiles to the traffic.
Scope
FortiGate.
Solution
SSL exemptions can be done for all Reputable websites, by category (trusted Webfilter categories), or with individual domains/addresses:
Note: SSL exemption can only be done with the Inspection Method: Full SSL Inspection.
Exempted traffic uses fewer firewall resources since traffic is not inspected further. Exemptions should be used with care to avoid skipping inspections for sensitive traffic.
GUI configuration steps (example):
2. Add the object to the exempt list in the SSL-SSH profile:
Note:
If the exempt list contains a wildcard address object/domain, FortiGate will check in the SNI (Server Name Indication) field to compare with the wildcard FQDN, which means that the SSL exempt list does not depend on the DNS resolution.
The SSL exemption list of FQDN objects behaves differently in flow-based and proxy-based inspection modes, see the article Technical Tip: SSL Exemption based on domain in Proxy-based Inspection.
Related articles:
Technical Tip: SSL exempt for Microsoft Windows Update
Technical Tip: How to configure wildcard-FQDN custom and group
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.