Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Akmostafa
New Contributor III

SSL certificate active probing

Hello team,

What is the benefit of the active probing feature while Fortigae can just wait for the server certificate in response to the original client hello.

What is the need of actively probe the certificate in a new connection originating from Fortigate?

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-FortiGate-does-TLS-Active-Probe/ta-p/3...

 

3 REPLIES 3
Akmostafa
New Contributor III

I have thought awhile about it.

I expect that this is due the fact that I recent TLS versions the server certificate is sent encrypted. Hence in flow based certificate inspection policies Fortigate should not have visibility on the certificate. 

 

Thus, the feature should not be required in either proxy or deep inspection deployments.

AEK

In TLS 1.3 the certificate is sent encrypted.

But for 1.2 and below I think one other reason is that the cert inspection may be time consuming. So cert active probing can enhance user experience.

AEK
AEK
Akmostafa
New Contributor III

I don't believe it would be any faster because fortigae has to start a new tcp connection and initiate TLS with the server to probe the certificate. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors