Hi there,
regarding a FortiGate in NGFW mode:
Anyone else wondering why it is not possible to use web categories in SSL inspection & authentication policies? You are able to us web categories in exemptions of the SSL/SSH profiles.
The most vendors I am used to (PAN, Cisco) offer this option.
Is there a way to do this or is there anything planed for the future releases? I am already on 7.0.2.
Thanks together.
Kind regards
Dominik
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I don't think I understand well you question, but if you intend to exempt or force SSH inspection for some categories then you should do it in your firewall policies, i.e: you create a firewall policy with SSH inspection enabled and with some web categories, and another FW policy for other web categories and just disable SSL inspection for it.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1696 | |
1091 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.