- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Configuring security profiles Fortigate
Hello,
I am planning to configure security profiles in some of the firewall policies that are on my FortiGate. My question about this is, if I need a valid/signed certificate installed on Fortigate and my hosts to inspect all traffic passing the FortiGate in order to inspect all data from packets and block certain traffic because it contains malware etc?
How does this work, can someone explain me?
Kind regards,
Geert
- « Previous
-
- 1
- 2
- Next »
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Geert_m ,
For example, if you want to use a web filter, you need to use ssl-deep inspection. if the website uses https FortiGate can't see the URL and URI because of that Fortigate can't block these websites.
Or if you want to use app control on FortiGate some signature needs to ssl-deep inspection. You can see these signatures in the application signatures menu. If the signature has a lock sign, this signature needs deep inspection for recognized.
For example
If you use proxy-based inspection mode. Fortigate automatically does SSL offload even if you don't add a deep inspection profile on your firewall policy.
NSE 4-5-6-7 OT Sec - ENT FW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Geert_m,
If you are planning to use deep inspection, you will need to install a trusted certificate to avoid certificate warning. Alternatively, you can import the FortiGate build-in certificate to the browser. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-deep-inspection-and-import-a...
Regards,

- « Previous
-
- 1
- 2
- Next »