Created on
03-02-2023
08:23 AM
Edited on
02-05-2024
04:43 AM
By
Jean-Philippe_P
Description | This article explains how the SSL Deep Inspection behaves in FortiGate and how it is correctly activated. |
Scope | All supported versions of FortiOS. |
Solution |
This example assumes a user is attempting to implement an SSL Deep Inspection for the first time.
In this case, the SSL Deep Inspection does not work as intended because the user still receives the original certificate from the website.
In order for FortiGate to activate the SSL Deep Inspection, it is first necessary to enable at least one of the security profiles. This can be Webfilter, Application Control, Antivirus, or IPS.
Note: Enabling the DNS filter will not activate the SSL Deep Inspection.
For example: after enabling Web filter, the deep inspection feature can be activated:
FortiGate has now activated the deep inspection:
Related document: Deep inspection | FortiGate / FortiOS 6.2.0 (fortinet.com) How to download the right certificate for SSL SSH inspection |