Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SivaG
New Contributor III

ForcePoint DLP integration with FortiGate using ICAP profile

One of our customer planning to integrate Forcepoint DLP with our FortiGate firewall using ICAP profile and require information regarding SSL inspection, specifically whether deep SSL inspection is necessary for this integration.

 

As deep inspection enables the firewall to decrypt, inspect, and re-encrypt encrypted traffic by acting as an intermediary, which requires distributing FortiGate’s CA certificate to all endpoints to avoid certificate warnings.

 

Could you please confirm if deep SSL deep inspection is mandatory for Forcepoint DLP integration with FortiGate? 

 

 

1 Solution
SivaG
New Contributor III

Hi everyone,

 

Meanwhile I checked with Fortinet TAC team and find the below response for my query,

 

Yes, it is mandatory to have the FGT-CA certificate in all endpoints. Review the below for more information

Push the certificate over GPO
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-distribute-a-Fortinet-CA-SSL-certif...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-Deep-Inspection-basic-behavior/ta-p/24...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-download-the-right-certificate-for-...

 

Regards,

SivaG

View solution in original post

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hi,

 

Did you have a look in our FortiDLP Knowledge Base?

https://community.fortinet.com/t5/FortiDLP/tkb-p/TKB55

 

You have a lot of articles that could help.

 

Regards,

Anthony

Anthony-Fortinet Community Team.
SivaG
New Contributor III

Hi everyone,

 

Meanwhile I checked with Fortinet TAC team and find the below response for my query,

 

Yes, it is mandatory to have the FGT-CA certificate in all endpoints. Review the below for more information

Push the certificate over GPO
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-distribute-a-Fortinet-CA-SSL-certif...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-Deep-Inspection-basic-behavior/ta-p/24...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-download-the-right-certificate-for-...

 

Regards,

SivaG

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors