Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jtfinley
Contributor

SSL Deep Packet Inspection

I have a curious project and a few questions came up about how Fortigate decrypt SSL' s specifically how it does it Man-in-the-middle to scan the traffic. 1 - Where does the SSL Decrypt the data take place ? And if NAT is in use 2 - Can this MiTM data stream be logged / recorded ?
3 REPLIES 3
AtiT
Valued Contributor

Hi, you can find some info about it on the page 164 - SSL content scanning and inspection http://docs.fortinet.com/uploaded/files/1082/fortigate-security_profiles-50.pdf

AtiT

AtiT
Sean_Toomey_FTNT

Hi jtfinley, The decryption / re-encryption takes place in the kernel. The firewall transparently proxies the connection in order to accomplish this. It works just fine if NAT is in use The stream of data is not exposed between being terminated and re-encrypted on the FortiGate. It is not possible therefore to see the unencrypted data this way. I sould note however if you have IPS or DLP policies match and you archive the packets/files then it may be possible to get access to unencrypted data this way, which is why you have to be cognizant of how you design the SSL policy and exemptions, and who has access to the archives in FAZ. There are significant enhancements to FortiOS 5.2 for SSL decryption and I would strongly suggest that you look into this version if you are going to enable that functionality. Also please read the documents thoroughly - this is not a protection you want to simply switch on - it takes planning and some trial and error to get the policy configured correctly and the clients working smoothly. This is the case with any device that does SSL Decryption, not just FortiGate. Hope this helps Cheers!
-- Sean Toomey, CISSP FCNSP Consulting Security Engineer (CSE) FORTINET— High Performance Network Security
Warren_Olson_FTNT

2 - Can this MiTM data stream be logged / recorded ?
If you did a capture on traffic you could probably load the private fortigate keys into wireshark to decrypt the SSL.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors