The problem with that is, that you totally lose the control of the other points certificate!!! This is a problem by design, which will spend us some grey hair in future ;)!The Fortigate can block invalid certificates.
That means ... each https website is shown up in the webbrowser with a fortinet certificate? And every time a user accesses a https website he has to click away all those certificate error messages? That´s not good ...I suspect it would be a wildcard certificate, signed by a root CA, which would need to be trusted by the client. Otherwise, since the FGT is terminating the SSL connection, it could present the page to the client as https://fqdn.of.fgt/proxy/https/fqdn.of.requested.site/page.extension As an example. Banks, etc wont be proxied as legislation does not permit it.
User | Count |
---|---|
2559 | |
1356 | |
795 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.