Hello,
till now I was sure that there are 2 possible modes: 1) certificate inspection (inspects the SSL handshake only) and 2) deep inspection (FG terminate SSL session from WAN side and encrypts packets with FG certificate towards LAN side). Today I'm reading "..Normally Fortigate is used for SSL inspection. It decrypts a copy of a packet in order to scan it, but doesn't actually terminate the SSL session. Instead, it passes along the encrypted packet (if it doesn't violate the security policies)..." - training material "FortiWEB Integrating Front-End SNAT & Load Balancers" page 15.
Hmm... Something new? I'm missed something? A mistake in the material? A new feature which will be in 5.4? ???
What do you think?
BR, Ramunas
Hmmm...specific to FortiWeb? This description does not have to apply to a Fortigate.
It was talked about FortiGate. The topic is "Should you use FortiWEB or FortiGate for SSL offloading?". May be it is mistake. If I understand correctly, the "man in the middle" can't decrypt SSL traffic (at least without supercomputer)
BR, Ramunas
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.