Hello everyone, I am managing a Fortigate 60E, which up until yesterday, was running FortiOS 6.2.1 build 0932(GA) for many months without any issue. I backed up the configuration and upgraded the system with the latest firmware and patches, following the proper upgrade path up to FortiOS v6.4.3 build1778 (GA) so the system is up to date. Ever since the upgrade, users complain about websites being blocked, general internet browsing delay and out of nowhere, "encrypted network traffic, untrusted certificate" prompt messages from their ESET antivirus, which i am not sure how relevant to our Fortigate device is but users claim that they started having these problems today which is after the FortiOS upgrade. Most of the websites being blocked have already been set up in the Policy & Objects ----> Addresses in the FQDN section to have access before the upgrade
I am running out of ideas atm and i am not sure if there is a way to properly downgrade the system back to 6.2.2 without creating bigger problems
Currently i am forced to turn Web filter off so everyone can work but this is not a solution of course.
Any ideas or anyone with similar problem ? Regards
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I guess you are using the built-in Factory certificate for SSL inspection. This is different in each firmware version. Either import it onto your users' PCs, or use a commercial cert which your users trust.
The complaint of ESET is correct...
Just a thought, Will restoring the old backup not restore the old Fortinet CA SSL certificate ?
I spend a good few hours last night trying to experiment and see if i can find a solution. In the end i downgraded back to the old firmware waiting for customer's feedback. The problem with the new firmware was that, not all users had connection issues after the upgrade but only a few
In my case i wasn't able to replicate the problem either. No ESET warnings no nothing.
Thank you all for your feedback
ede_pfau wrote:I'm also new to Fortigate, correct me if I'm wrong, I think the SSL CA certificate is tied to the box, not the firmware. Firmware upgrade should not effect the SSL certificate.I guess you are using the built-in Factory certificate for SSL inspection. This is different in each firmware version. Either import it onto your users' PCs, or use a commercial cert which your users trust.
The complaint of ESET is correct...
are you currently using proxy mode or flow mode?
do you still have access to the logs during the issue?
did the webfilter log show rating errors? did you check if you are HTTPS or UDP to communicate with FortiGuard?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1547 | |
1031 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.