Created on 01-01-2015 12:45 PM Edited on 09-24-2024 10:29 PM By Anthony_E
Description
This article describes that, occasionally, some applications may require exemption from SSL inspection to function properly, such as Skype. Exempting an application/domain/website in the SSL-SSH profile means that FortiGate will trust that connection and will no longer apply any security profile to the traffic.
Scope
FortiGate.
Solution
It is recommended to configure SSL exemptions through the GUI for ease of use, but this article will cover both the GUI and CLI methods.
Different options are available depending on the version of FortiGate.
SSL exemptions can be done with Reputable websites, by category (trusted Webfilter categories), or with individual domains/addresses:
The more exemptions are added, the fewer resources are needed by the firewall to process the traffic through additional UTM profiles. However, exemptions may represent a potential threat of accessing harmful resources.
Related article:
Technical Tip: SSL exempt for Microsoft Windows Update
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.