Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dbarroco
New Contributor III

SSL inspection rule with local certificate not being applied

Paired up 100D have two local certificates (with private key), one from own local CA for internal access, and one wildcard certificate bought from godaddy and imported using winssl for transformation.

I'm publishing internal web server using vip and SSH profile on that rule. I created a special SSH profile for web server protection using the certificate, but no matter what I always receive the certificate from the internal CA.

 

I tried to enable/disable the rule to certify that I'm hitting the right rule, recreated the profile, applied firewall policy using the CLI, applied other certificates to the SSH inpection profile, and seems no matter what i'm stuck with the local certificate.

 

The certificate from godaddy was imported first using the winssl help to create key and certificate file.

The self signed certificate was generated locally and submited to the internal CA using file.

 

Any ideas?

Thank you

David

3 REPLIES 3
dbarroco
New Contributor III

Just deleted the .local certificate, the domain CA certificate and the CRL update.

Refresh the page and I get still a local CA certificate.

dbarroco
New Contributor III

to whom it may concern, I found the solution here

http://sysmagazine.com/posts/210582/

 

Turns out I was trying to get the SSL Inspection rule to hand over my public certificate.

To do the SSL Offloading, the same way TMG does, I had to enable the Load Balance feature and create a Virtual Server and allow the incoming connection rule to refer that, instead of the virtual ip.

 

all done

Holy

Yep it´s Load Balancing is Reverse Proxy too

 

 

dbarroco wrote:

to whom it may concern, I found the solution here

http://sysmagazine.com/posts/210582/

 

Turns out I was trying to get the SSL Inspection rule to hand over my public certificate.

To do the SSL Offloading, the same way TMG does, I had to enable the Load Balance feature and create a Virtual Server and allow the incoming connection rule to refer that, instead of the virtual ip.

 

all done

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
Labels
Top Kudoed Authors