Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jamacouve
New Contributor

Cert error when connecting over cable to Office 365

Hi guys,

We are having an issue when ever someone connects via cable. A certificate error keeps popping up when connecting with ethernet. This does not happen over the WiFi. This has always been an issue. Nothing has changed. I have ensured that no cert inspection is enabled on the firewall. I have tried changed the system certificates and done a lot of research. This error is only applicable when trying to connect to Office 365.

Any insight ?

7 REPLIES 7
EMES
Contributor

When the certificate pops up is it issued by fortinet? Use IE and click on the pad lock next to the address bar.
jamacouve
New Contributor

Eugene.milon wrote:
When the certificate pops up is it issued by fortinet? Use IE and click on the pad lock next to the address bar.
Yup.

 

See below :

 

[link]http://imgur.com/a/aIrLP[/link]

EMES

There must an ssl/ssh inspection profile enabled on your policies if you are seeing that. Running a #diagnose debug flow. With some filters for your src ip will show you which policy I'd you are hitting.
jamacouve
New Contributor

Eugene.milon wrote:
There must an ssl/ssh inspection profile enabled on your policies if you are seeing that. Running a #diagnose debug flow. With some filters for your src ip will show you which policy I'd you are hitting.

I can see that no SSL inspection profiles are referenced anywhere on the firewall. This must be something else. I know which policy they are hitting and theres no SSL Inspection. 

 

If it means anything. Users are authed by FSSO.

hmtay_FTNT

Another reason the Certificate error could show up is if you have Office 365 blocked in Web Filter or App Control and you have replacement-message set to enable. In that case, the Fortigate will replace the Certificate to display the replacement message.

jamacouve

hmtay wrote:

Another reason the Certificate error could show up is if you have Office 365 blocked in Web Filter or App Control and you have replacement-message set to enable. In that case, the Fortigate will replace the Certificate to display the replacement message.

Valid point but then wouldn't wireless and wired have the same issue since they use the same profile?

 

FSSO can is the only difference. Wireless uses RSSO.

EMES

Just to be sure those user groups are FSSO and not Firewall user groups.

Labels
Top Kudoed Authors