Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GTNman
New Contributor

Anti=Virus not catching Infect HTTPS traffic.

I just went over to eicar.org to download the test malware files to see if my Fortigate 100a would pick them up as dangerous. Well, it worked perfect on the regular Port 80 traffic but anything over Port 443 secure would download just fine without warning. Is there something that needs to be set for the Fortigate to pick up the HTTPS traffic?
11 REPLIES 11
lmuir
New Contributor

The problem with that is, that you totally lose the control of the other points certificate!!! This is a problem by design, which will spend us some grey hair in future ;)!
The Fortigate can block invalid certificates.
That means ... each https website is shown up in the webbrowser with a fortinet certificate? And every time a user accesses a https website he has to click away all those certificate error messages? That´s not good ...
I suspect it would be a wildcard certificate, signed by a root CA, which would need to be trusted by the client. Otherwise, since the FGT is terminating the SSL connection, it could present the page to the client as https://fqdn.of.fgt/proxy/https/fqdn.of.requested.site/page.extension As an example. Banks, etc wont be proxied as legislation does not permit it.
UkWizard
New Contributor

I investigated this some time ago, and found that the only way it can be scanned is by a proxy, as the web browser has to have a proxy configured, so it will allow the proxy to decrypt the traffic by becoming the ' end point' of the vpn encryption. A man in the middle attack shouldn' t be possible in theory. I cannot imagine the fortigates ever having this functionality on its road map, as the cpu overhead would be too great. This is why no perimeter av scanning is a replacement for desktop AV, desktop AV should always be used.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors