Hello,
Gotta question regarding ssl certificate and SNI configuration. Im gonna use SNI solution, do I need to setup "certificates" on main page when creating main policy? please see screenshot. From my point of view no, cuz all certs info will be pointed in SNI policy, but I wannabe sure. I did test scenario where I put a cert there and SSL Labs showed me some errors, and sometimes I was getting "pr_end_of_file_error" - but im not sure if this was cuz of this.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Romank
Used it few years ago so if I'm not wrong the Certificate field should be the default one it the requested domain name is not in the SNI. I'll try to double check this info.
Hello romank,
You can leave it blank as Client Hello contains SNI that would match domain name in the SNI policy associated in server policy.
"pr_end_of_file_error" error seems surrounding on TLS problem. You can try to enable only TLS 1.2 and 1.3 and test again.
Thanks.
Regards,
Shafiq
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.