Hi All,
Is there a way to increase the limit of certificates on the SSL Inspection > Protecting SSL Server?
Apparently, limit of certicates that can be used is 10 as noted on the below article link and seems no resolution on it:
Reason for this is that we have mutliple domain names that needs https ssl inspection under one web server.
There is no way to increase max value. You may want to look at using a FortiWeb.
Agree with gfleming post.
A possible workaround could be re-issue some of those certificates in one multidomain SSL certificate; many commercial ssl certs provides multidomain SSL certificate, three as standard service, and more if you paid them for it.
regards
/ Abel
Thank you for your input gfleming and abelio.
Would it be expensive? Will have to look into the multi-domain SSL.
I was thinking if we have a workaround where we will set different firewall policy based on the FQDN. It would be like:
-Create a VIP via FQDN (instead of IP-based VIP)
-Create firewall policy for every FQDN VIP (this way, we could separate SSL cert per profile)
Currently testing this idea but so far not yet successful. Appreciate your thoughts about it.
Don't believe the FQDN VIP will work in this case as you only have one public IP address to map it to, correct?
User | Count |
---|---|
1923 | |
1144 | |
769 | |
447 | |
279 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.