Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Team-IT
New Contributor II

Issue with FORTINET Webfilter

Hi there,

 

some of my users are seeing this message, while others are totally accessing the page without issues. Once i restart the firewall (7.4.3) ALL users/ips are able to access the page without issues - so it's nothing related to a wrong policy (policy has NO IP-Filter but SSL Inspcection and VIP forwarding). I can reproduce it to happen again when changing the "SSL" certificate of the rule and changing it back:

Screenshot 2024-05-23 184433.png

 

Based on the log only SOME IP's (random and every time others) are affected:

 

Screenshot 2024-05-23 184350.png

 

Any hints on that how it can be solved without restarting? Where should i start to dig in deeper?

 

Side Fact:

PUBLIC IP -> VIP -> RULE 9 -> INTERNAL IP

the internal IP has in invalid certifacte - right domain, but no longer valid certificate; so sometimes this invalid certificate is used; sometimes the certificate in the fortigate ssl/ssh inspection category from "Protecting SSL Server" is used. After a reboot the invalid certificate is always ignored and the page loads for everybody.

 

Thanks...

3 REPLIES 3
AnthonyH
Staff
Staff

Hello Team-IT,

 

If you are using deep inspection for the VIP, I believe in the ssl/ssh inspection profile you are using in the firewall policy (rule 9) needs have the server certificate.

 

Here is an example:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-configuration-for-HTTPS-Virtua...

Technical Support Engineer,
Anthony.
Team-IT
New Contributor II

Rule 9 was the only place where i had the right certificate(s), cause there was no place on the "Virtual IP" where i can put it. I rebuild now from "Virtual IP" to "Virtual Server" and see if this is more "stable"

ToddRamirez
New Contributor

I am new here. Can I ask a question?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors