Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ZeroInterrupt
New Contributor

Any way to completely disable ssh/ssl inspection?

It is causing nothing but headaches for me, I am curious why it is a required setting whenever the UTM is turned on.
4 REPLIES 4
emnoc
Esteemed Contributor III

Make a no-inspection profile with nothing enable and add it to the fwpolicy that matches the src/dst or whatever you have. Do a search here on this site for examples.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
FortiAdam
Contributor II

in 5.0.x when you create your policy you can choose whether or not you want an SSL inspection profile enabled. Without that enabled your policy shouldn' t be intercepting any sort of SSL traffic for deep inspection. OP: Can you let us know what version of OS you are running so we can better assist you?
drak
New Contributor III

Can you please clarify ? As others have mentioned SSL Inspection is something you explicitly turn on at the policy level, rather than something system-wide. So, if it' s causing you some headache it' s a simple matter of disabling it on the policy you had previously activated.
emnoc
Esteemed Contributor III

As posted in a previous thread; config firewall ssl-ssh-profile edit " noinspection1" config https set ports 443 set status disable end config ftps set ports 990 set status disable end config imaps set ports 993 set status disable end config pop3s set ports 995 set status disable end config smtps set ports 465 set status disable end next or set the default with all status = disable this way that policy would be active when you enable the security inspections. This is not very complicated to do and will save you a lot of headaches. Remember this is a advance firewall and you have all controls on what you enable or not-enable.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors