Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Adam19892000
New Contributor II

Guest Devices certificate error via Web Filtering

Hi, 

 

Would someone be able to advise how to allow guest devices to use the web filtering without there being SSL inspection? I am unable to add any certificate onto the device but would like webpages to be blocked based on the web filtering policies. At the moment, the firewall is showing its certificate so the device doesn't trust the local certificate so brings an error before the web filtering block page is shown. 

 

I am utilising a separate VDOM for the guest system so it doesn't interfere with Internal use where we would utilise a trusted certificate for web filtering but unfortunately not possible in this case. 

 

I didn't have an issue with this on version 6.2.5 but having the issue on 6.4.6. 

 

Any help would be greatly appreciated. 

 

Adam

12 REPLIES 12
Adam19892000

Thanks Debbie. Testing so far on an iOS device, it just provides a page saying that it "cannot open the page because it could not establish a secure connection to the server." This obviously impacts user experience but it feels less so than the certificate error until I can fully resolve that. I do have a GoDaddy wildcard certificate but not sure I can use that as a local certificate within a specific VDOM.

Adam

Debbie_FTNT

Hey Adam,

with VDOMs set, I'm not sure if the FortiGate uses its global server certificate for the replacement pages or if specific ones can be set; let me see if I can find anything.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Adam19892000

Thanks Debbie, there’s no system option within the specific VDOM to set the certificate so I assume it’s a global setting if it is that cert that it uses for the block pages even though they can be edited per VDOM. 
Adam

Labels
Top Kudoed Authors