FGT200B 5.2.2
I enabled my first SSL deep inspection for inbound SSL traffic. I setup a VIP (see config below). I am protecting exchange 2010 OWA (aka webmail).
since enabling this SSL protection, most android clients still connect, but a small percentage of them stop syncing email after about 12 to 24 hours. If they reboot their phone the issue is resolved for 12 to 24 hours. when syncing stops, the android native email client shows a security warning and says their is a problem with the certificate. The android log files shows a common SSL error:
IOException javax.net.ssl.SSLPeerUnverifiedException: No peer certificate
Samsung S4, Android 4.4.2 and 5.0.1 - not working
Android 4.4.4 - no issues
I wish I knew what was wrong. :(
edit "Webmail_HTTPS" set comment "SSL for Webmail" set type server-load-balance set extip x.x.x.150 set extintf "any" set server-type https set http-ip-header enable set monitor "Ping-Mon" set ldb-method first-alive set extport 443 config realservers edit 1 set ip x.x.x.149 set port 443 set max-connections 9000 next end set ssl-mode full set ssl-certificate "webmail_exp2018" set ssl-min-version tls-1.0 set ssl-client-renegotiation secure next
FG200D 5.6.5 (HA) - primary [size="1"]FWF50B' s 4.3.x, FG60D's 5.2.x, FG60E's 5.4.x [Did my post help you? Please rate my post.][/size] FAZ-VM 5.6.5 | Fortimail 5.3.11 Network+, Security+
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
FYI, upgrading to 5.2.3 appears to fix this issue, even though it created a new issue with IE11 + TLS1.2 not working with SSL load balancing. That should be fixed in 5.2.4. *sigh*
FG200D 5.6.5 (HA) - primary [size="1"]FWF50B' s 4.3.x, FG60D's 5.2.x, FG60E's 5.4.x [Did my post help you? Please rate my post.][/size] FAZ-VM 5.6.5 | Fortimail 5.3.11 Network+, Security+
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1709 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.