FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ajoy
Staff
Staff
Article Id 249574
Description This article describes on 'Penetration test on FortiGate with SSL VPN port(443) open and displays the Content Security Policy as unsafe'.
Scope FortiGate v6.x.x -7.2.x.
Solution
 
 
pen.png

 

-The reason for including 'unsafe-xxx', blob, or data file system is certain times issues are seen loading web site or third-party web applications through the SSL VPN portal when it is necessary to load extra sources.

 

-Reports regarding 'unsafe-eval' and 'unsafe-inline' have already been reported and the developers concluded them to be necessary for the operation of the SSL VPN portal. To avoid function breakage, 'unsafe-eval' and 'unsafe-inline' are still acceptable.

Contributors