Hi All,
We are experiencing anomalous behavior with our FortiGate-3300E v7.2.7, build 1577, 240131 (GA.M). Specifically, when our clients attempt to access certain government websites, the firewall blocks the sessions for SSL, while allowing SSL_TLSv1.2 and SSL_TLSv1.3 protocols.
The issue persists even after adding the websites to the override web filter as exempt and configuring the Application Control for Network Service to allow all. Please refer to the attached screenshot for more details.
Your assistance in resolving this matter would be greatly appreciated.
Omran Mohamed
Best regards,
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
hi,
can you please check the SSL log from log&report -->SSL ... then filter source IP and check if any certificate error exists?
I found these as shown
Hi,
Please inspect the following link and test it on an isolated PC. Create a separate SSL profile for this PC to check if the issue is resolved.
Thank you very much for your support, @mahesh_pm . We will review the article, test the solution, and provide feedback.
Hi,
- As @mahesh_pm mentioned it looks like certificate probe issue.
- Can you check if the same issue is seen when you use policy in proxy mode instead of the flow mode?
- This could be matching a reported issue of 994101 as well.
Regards,
Shiva
Hi @smaruvala
Good day to you
yes we already using Proxy mode in the policy
Hi,
please create a new SSL profile with the below settings and enable it on policy.
if still the issue exists try the below activity .
on the cli
config firewall ssl-ssh-profile
edit SSL-TEST
config https
set cert-probe-failure allow
end
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.