Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
osaleem2_10
New Contributor III

Outbound SSL Full inspection

Hi,

 

I was using FortiGate version 7.2 with SSL Full inspection mode, and all was good. Now I have moved to 7.6.4, the latest version, but I think the configuration goes differently.

 

I have generated a CSR from (Certificate). And sign it through my local CA. Then import it as base-64. Then import it to my FortiGate. Now the certificate appears under my Local CA.

 

When I go to settings, I'm able to use this certificate. But at the SSL/SSH Profile, I'm not able to use this certificate for my SSL Profile.

 

Kindly let me know the right way to do SSL full inspection with a certificate that is signed by my local CA for version 7.6.4

 

OSALEEM2_10
OSALEEM2_10
2 REPLIES 2
ebilcari
Staff
Staff

The certificate used for deep inspection should have the "CA:TRUE" and able to sign other certificates:

signi.PNG

 

Make sure you have requested an intermediate CA from your local CA.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
osaleem2_10
New Contributor III

Thanks for your reply. Yes, it's the same as the mentioned pic. I'm able to use the signed cert in my setting for HTTPS browser. But still I'm not able to use it in the SSL security profile. I thought in the new version, there is a different way or I have to create from the security policy itself.

OSALEEM2_10
OSALEEM2_10
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors