FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
iskandar_lie
Staff
Staff
Article Id 247915
Description This article explains how the SSL Deep Inspection behaves in FortiGate and how it is correctly activated.   
Scope All supported versions of FortiOS.
Solution

This example assumes a user is attempting to implement an SSL Deep Inspection for the first time.

 

iskandar_lie_0-1677772567293.png

 

iskandar_lie_1-1677772652560.png

 

In this case, the SSL Deep Inspection does not work as intended because the user still receives the original certificate from the website.

 

iskandar_lie_2-1677772730654.png

  

In order for FortiGate to activate the SSL Deep Inspection, it is first necessary to enable at least one of the security profiles. This can be Webfilter, Application Control, Antivirus, or IPS.

 

Note: Enabling the DNS filter will not activate the SSL Deep Inspection. 

 

For example: after enabling Web filter, the deep inspection feature can be activated:

 

iskandar_lie_3-1677773539753.png

 

FortiGate has now activated the deep inspection:

 

iskandar_lie_4-1677773636342.png

 

Related document:

Deep inspection | FortiGate / FortiOS 6.2.0 (fortinet.com)

How to download the right certificate for SSL SSH inspection