Description | This article provides one of the reasons why FortiProxy is not able to send decrypted traffic despite proper configuration. |
Scope | FortiProxy. |
Solution |
A feature called 'Decrypted Traffic Mirror' is intended to decrypt encrypted traffic and send them via an intended interface to a remote server.
Even though FortiProxy is well configured with 'Decrypted Traffic Mirror', there is a situation where it may not work. Since traffic is expected to go through multiple policies on FortiProxy to match the best policy, TLS handshake tends to start with the very first policy that partially matches traffic.
Example:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.