FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
esalija
Staff
Staff
Article Id 362052
Description This article describes how to fix the 'SSL connection is blocked due to unable to retrieve servers certificate' error received in the SSL Events at Security Events.
Scope FortiGate.
Solution

After the upgrade to v7.4.5, the Apple devices with iCloud Private Relay turned on face the following SSL error. 

 

The 'SSL connection is blocked due to unable to retrieve the server's certification' error typically indicates a problem with the SSL certificate validation for those domains.

 

Capture1.PNG

 

  • To fix this issue, clone the SSL certificate inspection.
  • Disable the 'Server Name Indication (SNI)' to the new SSL Certificate Inspection.
  • Configure the New clone_SSL Certificate Inspection to the Firewall Policy.