When "SSL Reputable Websites" is active in "Security Profiles -> SSL/SSH Inspection" the system doesn't block some addresses (ex. facebook.com) that normally are blocked by policy and also application.
Obviously with "SSL Reputable Websites" disabled, the addresses are locked correctly.
Is it normal? Can "Web fiter" have priority on "SSL Exemptions"?
Thanks to all.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I think your using the wrong Security Profile for attempting control of HTTPS websites. The "SSL Reputable Websites" is used to exempt sites from SSL-deep-inspection it has nothing to do with URL filtering. You do this , if you want trust that site and have SSL inspection issues ( so why would you need URL filtering ..you just exempt it ).
Next, because we have no SSL inspection, how do you know what the customer is going to ( Host: header is encrypted ) and next unless you inspect SNI, you have no means to inspect the URL. ( So again you just exempt it !)
Your firewall is performing correctly btw ;)
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.