Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ciscomemo
New Contributor

SSL Inspection and certificate error

I understand that if I want to do HTTPs inspection I need to enable SSL inspection on fortinet but this gives error on users browser when opening https websites. This is because we need to install fortinet certificate in user PC , once this is done error goes away . 

 

In guest case senerios where users bring in their own device and we dont have option to install this certificate on each of those devices how would https blocking work ? I believe that we need to instsall the ssl certificate because our certificate is a private generated one , if we purchase a certificate from a known company like https://www.rapidssl.com etc and use that certificate in fortinet and not the default one of fortinet , we might not need to put that certificate in each user PC  because this certificate would be globally trusted . 

 

Please advise if i am correct. 

14 REPLIES 14
Bromont_FTNT

That screenshot shows a non-secure page and the embeded video is dailymotion which also likely is not requested over https

 

do you have screenshots of HTTPS blocked pages?

ciscomemo

Bromont_FTNT

oreedo_3_error.png is the message from the ISP? Looks like they can't display the blocked page properly over HTTPS either

ciscomemo

yes that page is from the ISP. Do you think they are running some sort of basic certificate level inspection and one can achieve all of these things using basic methods  

 

I have implmented certificate inspection with a few customers and found out that if u try https it bypassses the firewall . Also I have seen a couple of times while doing the deep inspection that error page does show up with http but with https it will just say timeout or would keep on loading ...

Bromont_FTNT

ok so if you do certificate inspection allowed pages will pass ok but blocked pages will get a certificate error because the Fortigate needs to do full SSL in order to display the blocked page message. Looks like the ISP is probably doing certificate inspection and for blocked pages just sends a tcp reset instead of a blocked page message.

Labels
Top Kudoed Authors