- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Trouble with SSL inspection
Hello and sorry for my english,
I have basic inspection configuration, like this :
but i have a lot of SSL anomaly in security events, more than 22,000 and sites are blocked; for example :
to website mask.apple-dns.net
Event Type : ssl-anomaly
Event Subtype : certificate-probe-failed
what can i do ?
thanks a lot
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
This is because mask.apple-dns.net on TCP 443 has no certificate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
so what i have to do ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
But what are you trying to do? I see https;//mask.apple-dns.net is not a valid location (no Web server behind). So the question is why are you trying to access this location?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @mulbzh ,
If you test this website:
https://www.ssllabs.com/ssltest/analyze.html?d=mask.apple-dns.net
You will see that all the entries are failed.
Not sure what you need to do with this website, but you may add it to the SSL Inspection Exempt list.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i have got many and many others erros like this :
also i can't do SSL exceptin, this option is only enable when SSL Deep inspection is selected
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From your screenshot I tested the IP that have blocked sessions and all don't have a certificate, so SSL can't take place, just like for mask.apple-dns.net.
But still don't know what you are trying to do. Do you or your users have troubles using some applications?
