Created on 07-14-2009 02:52 PM Edited on 06-02-2022 09:40 AM
Description
FortiOS versions 4.0 MR3 and 5.0.x include a deep scanning option, that includes support for scanning encrypted protocols when used with Anti Virus and Webfilter Profiles. To run this security information, server and client certificates must be obtained. This article describes the basic steps needed to enable this feature.
Scope
Solution
FortiOS firmware version 4.0 MR3:
Go to Policy > Protocol Options > HTTPS > Deep Scan > Enable and select apply to save the changes.
To avoid the warning message that pops up in the browser when using a custom certificate, a key and a password will need to be loaded onto the FortiGate, and a certificate will have to be loaded into the PCs web browser.
Related Articles
Troubleshooting Tip : Verifying server certificate on SSL Inspection
Technical Note: FortiGate HTTPS web URL filtering and HTTPS FortiGuard web filtering
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.