I've been building some policies to control egress and I came across and interesting situation. I was building a policy for Apt (apt-get). And it works perfectly fine. Except for when a server has an additional repository installed. These are all Debian 12. And everything works except for when the Docker repos refresh. In which case Apt starts getting back 403's and 401s. Toggling the policy on and off directly affects whether Apt works correctly or not.
So, I'm trying figure out if this is my outbound SSL inspection policy meddling with a pinned cert or something I need to modify in my policy.
Thanks all for the thoughts on this.
I don't think there's any such thing as precedence. If you have both enabled then they must both permit the traffic for it to be allowed. If the WF permits but AC blocks then the session is blocked.
What do you see in the related FGT's deny traffic log? It should provide the detailed reason for which it has denied the traffic. Check also the security log in the related deny traffic log, to see which security profile has denied it and why.
| User | Count |
|---|---|
| 2806 | |
| 1426 | |
| 812 | |
| 759 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.