FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
carabhavi
Staff
Staff
Article Id 196840

Description

 

This article describes how to enable a deep inspection profile in the IPv4 policy and import a certificate in the browser to avoid certificate warnings.

 

Scope

 

FortiGate.

Solution

 

Note: The following steps must be undertaken in flow mode. They will not have the intended results in proxy mode.
 
To import Fortinet_CA_SSL to the browser:
 
  1. On the FortiGate, go to Security Profiles -> SSL/SSH Inspection and select 'deep-inspection'.
  2. The default CA Certificate is Fortinet_CA_SSL.
  3. Select 'Download Certificate'.

 
  1. On the user's PC, select the certificate file and select 'Open'.
  2. Select 'Install Certificate' to launch the certificate import wizard and use the wizard to install the certificate into the trusted root certificate authorities store.
 
install.png
local-mach.png
cert store.png
If a security warning appears, select 'Yes' to install the certificate.

Note:
Install a certificate with trusted root authority only.
 
 
 
The image above explains the steps to enable deep inspection in the IPv4 policy.
 
These steps are as follows:
 
  1. On the FortiGate, go to Policy and Objects -> IPv4 Policy and edit the traffic policy.
  2. Under the section 'SSL Inspection', select the created SSL deep inspection profile.
  3. Select Apply or Ok to save the changes.

Obtain, set up, and download an SSL certificate package from a certificate authority.

SSL certificate packages can be purchased from any Certificate Authority (CA), such as DigiCert, GoDaddy, or GlobalSign.

 

 

The process for purchasing, setting up, and downloading a certificate will vary depending on the CA that is used, and if a CSR must be generated on the FortiGate.

 

To purchase a certificate package:
  1. Create an account with the chosen vendor, or use the account that have been used to purchase the domain.
  2. Locate the SSL Certificates page.
  3. Purchase a basic SSL certificate for domain validation only. If required, a more secure SSL certificate can be purchased.
  4. If required, load the CSR, either by uploading the text file or copying and pasting the contents into the requisite text box. See Generate a CSR for information on generating the CSR on the FortiGate.
  5. If required, set the server type to Other.
  6. Verify the certificate per the requirements of the CA.
  7. Download the signed certificate to the computer.
  8. Import the signed certificate into the FortiGate; see Import the signed certificate into your FortiGate.

Generate a CSR.

Some CAs can auto-generate the CSR during the signing process, or provide tools for creating CSRs. If necessary, a CSR can be created in the FortiGate device’s GUI.

 

To generate a CSR on the FortiGate:
  1. Go to System -> Certificates. By default, the Certificate option is not visible, see Feature visibility for information.
  2. Select Generate. The Generate Certificate Signing Request page opens.
 
Generate a CSR.png              
  1. Configure the CSR request:
    • Ensure that the certificate has a unique name.
    • Set the ID Type to Domain Name and enter a Domain Name.
    • An email address is required.
    • Ensure that the Key Size is set to 2048 Bits.
    • Set the Enrollment Method to File Based.

  2. Select OK.

    The CSR will be added to the certificate list with a status of PENDING.

  3. In the certificate list, select the new CSR then select Download to save the CSR to the computer.

    The CSR file can be opened in any text editor, and will resemble the following:

 
 
output.png

Import the signed certificate into the FortiGate.

To import the signed certificate into the FortiGate:
  1. Unzip the file downloaded from the CA.

    There should be two CRT files: a CA certificate with a bundle in the file name, and a local certificate.

  2. Log in to the FortiGate unit and go to System -> Certificates.
  3. Select Import -> Local Certificate.
                                                      
Import the signed certificate into your FortiGate.png

 

  1. Upload the local certificate file, then select OK.
  2. The status of the certificate will change from PENDING to OK.
  3. Select Import -> CA Certificate.
  4. Set the Type to File, upload the CA certificate file, and then select OK.

    The CA certificate will be listed in the CA Certificates section of the certificates list.