Hello team,
What is the benefit of the active probing feature while Fortigae can just wait for the server certificate in response to the original client hello.
What is the need of actively probe the certificate in a new connection originating from Fortigate?
I have thought awhile about it.
I expect that this is due the fact that I recent TLS versions the server certificate is sent encrypted. Hence in flow based certificate inspection policies Fortigate should not have visibility on the certificate.
Thus, the feature should not be required in either proxy or deep inspection deployments.
In TLS 1.3 the certificate is sent encrypted.
But for 1.2 and below I think one other reason is that the cert inspection may be time consuming. So cert active probing can enhance user experience.
I don't believe it would be any faster because fortigae has to start a new tcp connection and initiate TLS with the server to probe the certificate.
| User | Count |
|---|---|
| 2910 | |
| 1451 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.