Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Umesh
Contributor II

SSL deep inspection log

Hi All,

 

I have some quires which is raising question in my mind.

 

Can I see following information in logs If I enable deep inspection into the Firewall policy.

 

Details information :-

1. user id

2. password

 

Any information that end user enter into his/her browser to gain access any https/http.

 

I have installed CA certificate into end user machine of Foritgate Firewall (SSL certificate)

 

Firewall policy's inspection mode is proxy based inspection

 

Also applied - security profile such as - Antivirus, webfilter profile (proxy mode), application control ( proxy mode), IPS, Full SSL deep inspection.

 

Still unable to see the which I want - encryption / decryption packets.

 

 

Do you have any experience on that please share your view. so that I can resolve my issue.

 

I have gone through several article still not able to get any clue regarding this.

 

 

Thanks for your support.

 

 

 

 

 

 

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Umesh

No, those information will not appear in logs even with deep inspection.

However they can be seen with packet capture. But not in logs.

Besides there is an option in SSL inspection profile to exempt some sites from deep inspection. Here for example you should exempt banks, medical and other sites or categories with sensitive info.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors