I'm trying to skip ssl inspection for a domain.
I tried adding the domain (both the FQDN and wildcard) in the SSL Inspection profile as "exempt" but requests still get sent the self-signed fortigate certificate.
I added a policy with the site set as the destination and set it to skip SSL inspection (as well as skipping the other security profiles, to try and get it working.)
I put it into learn mode to ensure it was receiving traffic, then enabled it.
My understanding is only one policy is applied; so when this policy matches it should skip the checks and not fall through to the others.
The problem I'm having is intermittent! Sometimes I get the websites SSL certificate and the request goes normally. Other times, I get the fortigate self-signed certificate. My target website uses HSTS so this makes the self-signed certificate error un-skippable.
I'm baffled, but hopefully I've just missed something obvious.
Fortigate 200D, with v6.0.5
User | Count |
---|---|
2640 | |
1402 | |
810 | |
686 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.