at first a happy new year to all.
I have a Problem when i enable ssl deep-Inspection and surfing through the Web.
I noticed that some sites loading only if i reload the site twice.
Sometimes but not often I get a "ssl_error_bad_mac_read" error in Firefox.
It also went gone when I reload the site.
It is relative often reproducible when I am surfing through the fortinet forum.
I am using the build in fortinet proxy certificate which CA is certainly imported in the browser under trusted ca authorities
I have checked this with some other browsers and on other machines to rule out that
it is a browser/machine problem only.
The goal why i have enabled deep inspection is to use antivirus in https.
Allow Invalid SSL Certificates and Log Invalid Certificates are both enabled
but I get no errors.
Like I said it is not on all sites but when I noticed that and loading process was too long then I reload the site and now it comes up. Then I figured out when deep-inspection is turned off then all runs well.
How can I check what happens. Sniffing the traffic gave no usefull hints until now.
I see sometimes only the req but no ack.
Any hints for cli commands that can help to encircle the problem more precisely?
My device is a FGT 60D with V5.2.5
Any help is appreciated.
1:Isolate a fw-policy with ssl deep-inspection for one site only
2:Run the diag debug app ssl -1 command review the output
3:test using various browser
I can't give you a exact reason for your problem but does it happen with fire-fox, ie and chrome? to the same site ? Chrome seems to exhibit issues that's not seen n IE or Safari or FFOX. It also has better support and security and support SHA256 right out the box.
Yes i did.
I tried it with debug level -1 and 7 (highest value)
diag debug sslvpn -1
diag debug flow tracert start
diag debug flow show console enable
diag debug enable
Fortigate-60D # diag debug info
debug output: enable
console timestamp: disable
console no user log message: disable
sslvpn debug level: -1 (0xffffffff)
CLI debug level: 3
Notice that there exists only "sslvpn" not ssl.
That seems why i see nothing.
Surfing through many ssl sites also these which makes trouble but nothing is shown.
I don't see also in the cli manual any references for ssl only sslvpn is described.
The Wiki says something about this in conjunction with SSL/TLS offloading.
Don't know if the 60D has this capability. It has an Asic (CP0) but maybe it is handled by software not Hardware.
By the way i follow also the Thread NOW! Fortios 5.2.5 who it seems to be issues with deep inspection in the same way.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.