Description |
This article describes how to control self-originated traffic when SSL inspection with flow mode is configured.
When ssl-inspection is used in flow mode, FortiGate will create some self-originated outgoing connections for the various certificate operations. These self-originated connections will use the outgoing interface IP according to the routing table by default. In some customer environments, these connections will not be allowed. The article will explain what these connections are and how to control source IP for these connections. |
Scope | FortiGate v7.0 and above. |
Solution |
When SSL inspection in flow mode is being used, FortiGate will create outgoing connections for two purposes:
TLS active probe sessions will be seen below in the session table. They will be outgoing HTTPS sessions:
In specific cases, FortiGate may log local traffic entries with the action 'timeout' when a user attempts to access a web resource. This generally indicates that the FortiGate is unable to establish a connection to the remote server, often due to missing or unreachable routing.
To suppress such log entries, the sni-server-cert-check option can be disabled within the applied certificate inspection profile.
Local Traffic:
date=2025-06-10 time=10:52:15 eventtime=1749523934992147456 tz="+0800" logid="0001000014" type="traffic" subtype="local" level="notice" vd="GNET_Pri" srcip=10.99.223.211 srcport=18213 srcintf="GNET_Pri" srcintfrole="undefined" dstip=10.106.2.70 dstport=8080 dstintf="port1" dstintfrole="wan" srccountry="Reserved" dstcountry="Reserved" sessionid=63998658 proto=6 action="timeout" policyid=0 service="HTTP_return" trandisp="noop" app="HTTP_return" duration=13 sentbyte=180 rcvdbyte=0 sentpkt=3 rcvdpkt=0
session info: proto=6 proto_state=02 duration=10 expire=2 timeout=1200 flags=00000000 socktype=0 sockport=0 av_idx=0 use=3 AIA sessions can be controlled with the following configuration option:
config vpn certificate setting set source-ip {string} <----- Source IP address for dynamic AIA and OCSP queries. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.