Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MohammedAlrawi
New Contributor II

SSL inspection on inbound traffic

Hi,

 

I have been given a task to activate the SSL Certificate inspection (not full) on the inbound traffic (on published servers lets say) so I tried to search for almost one week but couldn't get anything on the inbound traffic SSL inspection I have some questions if you can help me with that I would really appreciate it :

1-What is the difference between Full inspection and SSL Certificate inspection and which one would be best practice? as am trying to test out some stuff on the published test server.

2-What is the best practice for SSL Certificate and just to give you more information we user VIP as I found the some information it says that the traffic would be decrypted when coming to the firewall and traffic would be inspected then rencrypted the question here is which CA do I use in the certificate option ? 
3-anything related links sources would be really appreciated for more info on the inbound SSL Certificate inspection as I tried to search found little info I know am doing something wrong here for searching but my English isn't my first language and am still in my first year in networking.

 

Many thanks in advance.

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Mohamed

Here is for inbound traffic when you have a published server (I suppose it is for a Web server):

  1. Certificate inspection only inspect the SSL certificate (validity, expiration, CA, ...)n while deep inspection decrypt the traffic (for content analysis) then re-encrypt it again (if needed, that's why here VS is better than VIP). Certificate inspection will not help you in anything here, unless you have a WAF behind the firewall (I mean dedicated WAF, not FortiGate's embedded WAF). If you have a dedicated WAF then you don't need deep inspection at FG level since the WAF is application firewall ideal for HTTP inspection
  2. For public server you will need a certificate signed by public CA. If this for private usage then you just need it from your Corp's private CA
  3. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-configuration-for-HTTPS-Virtua...

Hope it helps

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors