FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
mpankovski_FTNT
Article Id 198659

Description

 
This article explains how to configure the exemption of Windows updates from SSL inspection.

Refer to the related article for earlier FortiOS versions.


Scope

 
FortiOS v7.0+.


Solution

 
This can be configured through the FortiGate GUI.

  • Go to Policy & Objects -> Objects -> Addresses -> Create address objects of type FQDN for each domain.

kb2.png

 

  • Verify the FQDN address object status by running the following CLI command:
 
diagnose firewall fqdn list-ip
 
Example :
 

diagnose firewall fqdn list-ip | grep windows

fqdn_u 0x546ff743 windowsupdate.microsoft.com: type:(1) ID(99) count(1) generation(1) data_len:13 flag: 1

ip list: (1 ip in total)

ip: 20.72.235.82

Total ip fqdn range blocks: 1.

Total ip fqdn addresses: 1.



  • Go to Policy & Objects -> Policy -> SSL/SSH Inspection -> Select Full SSL Inspection Profile -> Under 'Exempt from SSL Inspection' add the Addresses that were previously entered in step 1.

kb1.png

Related Article:

Technical Note : FortiOS How to use SSL exemption for Microsoft Windows Updates