Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Erik-dft
New Contributor

SSL sites suddenly getting blocked all over (different Fortigates)

We manage a few dozen Fortigate units for our customers.  Starting yesterday, sites started getting blocked with SSL errors.  

 

This is across different fortigates (60E to 200F) and different versions 6.4x to 7.0.4

 

Turning off all UTM features of a policy seem to help.  But it's very weird.

 

Firefox reports it as "NET::ERR_CERT_COMMON_NAME_INVALID"

 

But the site is just fine and so is the cert.  It's happening on big sites like banks and even the fortinet support site.

 

I also saw a log message that fortinet's DNS server went unavailable for a bit.

 

anyone else having issues like this?

 

2 REPLIES 2
lior
New Contributor III

Yes, mine started blocking sites too with this message:

 

FORTINET Webfilter

This Connection is Invalid. SSL certificate expired.

SveN2
New Contributor

Hi, not sure if that's what you have, but when I read "let's encrypt" this came to my mind:

https://www.fortinet.com/blog/psirt-blogs/fortinet-and-expiring-lets-encrypt-certificates

have a nice day

Labels
Top Kudoed Authors