Hello,
Issue: Limited Network message for network connection on android devices
I have about 60 Smart-boards (Android OS) which half of them are connected through cable and the other half through wireless to my network, when I try to apply firewall policy with SSL deep inspection over their traffic to the internet, these smart-boards show a warning message that "Some apps and services may not work due to limited connectivity. Use anyway?" then I have to confirm it so that it gets connected, and this message appears constantly which it creates problem for me.
It can be solved if I add a category exemption in SSL Profile for "Search engines and Portals" but this not a good solution since I need to have more control over filtering.
On PCs with windows 11 I do not get that message.
I already installed the Certificate on all of this smart-boards as "Installed for VPN and apps" and also for "Installed for Wi-Fi". I installed for both of them.
But the result is the same.
I would appreciate your help.
Thanks.
What is the firmware version on Fortigate? Are you connecting with Forticlient ssl-vpn? If yes, are you using EMS or free version?
Hi,
The FortiOS version is 7.4.3
I have configured SSL-VPN tunnel on the firewall and I use fortiClient to get connected to the network. But I establish the VPN connection sometimes not always.
and for the remaining of your question I have the below screenshot:
Please check this similar discussion forum and take pcap on Android devices to identify the certificate used by the problematic applications. applications. https://community.fortinet.com/t5/Support-Forum/SSL-Deep-Inspection-create-Internet-issue-for-Smartp...rue
You may need to exempt a few apps from deep inspection due to certificate pinning, please refer to this forum post: https://community.fortinet.com/t5/Support-Forum/Google-Play-Store-Not-Working/m-p/90114?m=170981
Hi Anxious
Some applications use HSTS, refusing deep inspection (MITM) even if you install the required CA on the clients so they trust your FG. It is probably your case. You just need to check if your applications are HSTS.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.