Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
wesg
New Contributor

Policy to exclude filtering intermittently applies SSL inspection

I'm trying to skip ssl inspection for a domain.

 

I tried adding the domain (both the FQDN and wildcard) in the SSL Inspection profile as "exempt" but requests still get sent the self-signed fortigate certificate.

 

I added a policy with the site set as the destination and set it to skip SSL inspection (as well as skipping the other security profiles, to try and get it working.)

I put it into learn mode to ensure it was receiving traffic, then enabled it.

 

My understanding is only one policy is applied; so when this policy matches it should skip the checks and not fall through to the others.

 

The problem I'm having is intermittent! Sometimes I get the websites SSL certificate and the request goes normally. Other times, I get the fortigate self-signed certificate. My target website uses HSTS so this makes the self-signed certificate error un-skippable.

 

I'm baffled, but hopefully I've just missed something obvious.

 

Fortigate 200D, with v6.0.5

 

0 REPLIES 0
Labels
Top Kudoed Authors