Description | This article describes how to resolve an issue where users cannot access certain websites and their traffic is denied because of an explicit proxy policy, even when a deep inspection SSL profile has been enabled on one of the explicit proxy policies. |
Scope | SWG SSO. |
Solution |
Some websites are denied with a 'Traffic denied because of explicit proxy policy' message because the traffic has triggered the 'Implicit Deny' policy. Deep inspection has enabled on the SWG policy.
Check the SSL inspection profile:
Go to Configuration -> Security -> SSL profile -> Configure SSL -> Check the Exemptions list.
Example of Finance and Banking category: alipay.com.
Blocked page on client browser:
From the FortiSASE portal, the traffic log will show as follows:
To fix the issue, remove the URL category from the SSL exemption list:
|