We've recently upgraded firmware on our 901G to v7.2.11 (from v7.2.8) and since then we're experiencing random internet slowdowns across our sites.
Memory and CPU usage are running at normal levels and it appears there is plenty of available bandwidth on our primary Internet Circuit.
We use proxy based inspection, with SSL certificate inspection selected. I have found today that if I change certificate inspection to no inspection on the policy that we have had no internet slow downs since.
Has something changed between 7.2.8 (where performance was fine) and 7.2.11 where we are seeing these issues? It is worth noting that due to a GUI bug I wasn't aware of the FortiGate ignored the recommended upgrade path and went straight to 7.2.11.
I have seen this article How to fix 'SSL connection is blocked... - Fortinet Community however we are not using flow based.
I am also seeing floods of "Server certificate is re-signed as untrusted, certificate-status: untrusted." in the security logs, could this be a contributing factor?
For this issue, you should log a ticket with TAC, they may monitor and investigate faster.
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.