Hey everyone,
Currently attempting to enable SSL inspection/MITM on a 80C and it doesn't seem to be working.
[ul]Relevant configurations : Security profile : https://i.imgur.com/lT5y8aL.png FW rule with applied profile : https://i.imgur.com/u3OwQAw.png Traffic hitting the FW and the correct policy : https://i.imgur.com/Pvx5pPC.png
Is the SSL inspection feature behind the paid license? Anything else I could try to properly tshoot this?
Let me know if there is anything else I can provide.
Thanks!
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
What do you mean that it is not working.
You have to use SSL inspection with some other security profiles such as IPS or Web Filter.
Orestis Nikolaidis
Network Engineer/IT Administrator
What do you mean that it is not working.
You have to use SSL inspection with some other security profiles such as IPS or Web Filter.
Orestis Nikolaidis
Network Engineer/IT Administrator
orani wrote:That was it! I tried with a dummy web filter and it does intercept the SSL traffic now.What do you mean that it is not working.
You have to use SSL inspection with some other security profiles such as IPS or Web Filter.
I am now trying to dump the decrypted SSL traffic. I've bolded the relevant commands. That said, I am not seeing any traffic on that interface. Anything else I should try?
FGT-LAURENT-DREAMHACK # show firewall policy 1 config firewall policy edit 1 set name "ssl-inspection" set srcintf "internal" set dstintf "wan1" set srcaddr "all" set dstaddr "all" set action accept set schedule "always" set service "ALL" set utm-status enable set logtraffic all set ssl-mirror enable set ssl-mirror-intf "wan2" set webfilter-profile "web-filter-flow" set profile-protocol-options "default" set ssl-ssh-profile "test-all" set nat enable next end
Thanks!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.