| Description | This article describes an issue where the FortiGate firewall does not block Facebook traffic with the Application Control Security Profile when certificate-inspection is enabled in the firewall policy. |
| Scope | FortiGate v7.4.3, v7.4.4. |
| Solution |
When the application control security profile is configured to block the Social Media category and a firewall policy is configured with ssl-ssh-profile 'certificate-inspection', FortiGate fails to block Facebook and classifies its category as 'unknown'. config application list config firewall policy Forward Traffic logs:
This issue has been resolved in v7.4.8 and v7.6.1. Workaround:
To get more detail about the feature proxy-inline-ips please review the below article: Technical Tip: Proxy Inline Intrusion Prevention System feature in FortiOS |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.