I'm enabling SSL deep inspection for the first time, and would like to test it on a single workstation before deploying.
I have created a new SSL inspection profile called "prod-deep-inspection" and downloaded the certificate for it. Before I install the certificate I want to test and make sure this workstation shows errors in the browser.
I've created an IPV4 policy under "data (internal1) -> SD-WAN":
[ul]But when I browse on the workstation I don't get any certificate errors, and the browser shows the website certificate.
Is there something wrong with my policy that's causing it to not produce errors on this workstation?
When I look at traffic logs, I can see that my policy, #24, is applying.
I wrote this up as a sure 100% way to know SSL inspection
http://socpuppet.blogspot.com/2018/05/av-with-https-inspection-fortios.html
But I would start by looking at the firewall ssl-inspection profile "prod-deep-inspection" and a diag debug flow
Ken Felix
PCNSE
NSE
StrongSwan
Which settings do you have set in Security Profiles > SSL Inspection, prod-deep-inspection ? Esp. do you scan all ports or just 443?
Enable SSL Inspection of: Multiple clients connecting to multiple servers
Inspection method: Full
CA Certificate: Fortinet_CA_SSL (the default certificate, I didn't change anything here)
Untrusted SSL Certificates: Allow
RPC over HTTPS: Disabled
Inspecting HTTPS, SMTPS, POP3S, IMAPS, FTPS
Exempt from SSL Inspection: reputable websites disabled.
Allow invalid ssl certificates: disabled
Log SSL anomalies: enabled
If I am not mistaken - applying SSH profile won't do anything on its own - it only comes into play when another policy like Anti-virus or Web filter is also being looked at. So you would also need your web filter policy applied to that rule for the SSH Inspection to occur when browsing to an Https site
I am experiencing the same thing with my Fortigate 1200D. Google has knowledge base article: https://support.google.com/chrome/a/answer/3504943?hl=en&ref_topic=3504941
where inside are useful tests for chromebooks and a note on how the chromebooks require a PEM based certificate.
I opened a ticket with Fortinet support.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.