We used to do extensive app troubleshooting on 7.2 decrypting the traffic using a trusted ROOT CA installed on the client machine.
After upgrading to 7.4, it no longer works, what we would do is (on 7.2):
create a loopback interface, create a decrypted-traffic-mirror with the loopback bound to it, create a firewall policy with decrypted-traffic-mirror enabled to the mirror. then create a firewall sniffer with the loopback interface. and voila, plain text https came out n pcap form.
the issue now seems to be the firewall sniffer has gone, and the new packet capture thing does not let us use loopback as an interface. Has anyone got this working and could share the steps?
Hello flamer,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
Hello flamer,
I found this solution. Can you tell us if it helps, please?
In FortiOS 7.4, the packet capture process has changed, and the previous method using a loopback interface for decrypted traffic mirroring may not be directly applicable. Here are the steps to capture decrypted traffic in FortiOS 7.4:
If the loopback interface cannot be used directly in the new packet capture tool, consider using a dedicated interface for traffic mirroring and capturing traffic on that interface instead.
User | Count |
---|---|
2626 | |
1400 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.