Created on 09-22-2017 02:00 PM Edited on 04-07-2022 01:16 PM By Anonymous
Description
This article explains how to exempt the Microsoft OneDrive application through FortiGate when SSL deep inspection is enabled in policy.
Solution
Microsoft OneDrive application may experience a sync issue when SSL deep inspection is applied in policy on the FortiGate.
In order to exempt the OneDrive from SSL deep inspection, make sure to include the following domains in the exemptions list.
Steps:
1) Create address objects: browse to Policy & Objects -> Addresses -> Create New -> Address -> Type -> Wildcard FQDN
Create a wildcard FQDN for all addresses as follows. Choose any name then type the address in the wildcard FQDN field. Repeat this operation to create all the addresses one by one.
*.live.com
*.microsoft.com
*.sharepoint.com
*.svc.ms
*.windows.net
*.windows.com
*.microsoftonline.com
*.microsoftonline-p.com
*.onedrive.com
2) Create an address group: browse to Policy & Objects -> Addresses -> Create New -> Address Group
Then select the address object created in step 1.
3) Select the address group in the SSL deep inspection profile:
4) Then apply the SSL profile to the policy if it is not applied.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.