Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jonlarsen
New Contributor

SSL deep inspection client-cert-request

I have an SSL inspection profile set to deep-inspection.

What does this option actually do to the SSL handshake? And will the Fortigate still be able to inspect the traffic?

"set client-cert-request bypass"

1 Solution
abelio
SuperUser
SuperUser

Hi

By default, those SSL sessions using  "client-certificates"  bypass the SSL inspection.

You could also control that using inspect or block the traffic

 

regards




/ Abel

View solution in original post

regards / Abel
2 REPLIES 2
abelio
SuperUser
SuperUser

Hi

By default, those SSL sessions using  "client-certificates"  bypass the SSL inspection.

You could also control that using inspect or block the traffic

 

regards




/ Abel

regards / Abel
jonlarsen

Hi :) Okay, I have changed the SSL inspection on HTTPS from 443 to all ports, and this also disabled the bypass setting for client-certificates. I see I can change it in the CLI under "config ssl".

 

Thanks!

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors