Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mulbzh
New Contributor II

Trouble with SSL inspection

Hello and sorry for my english,

I have basic inspection configuration, like this :
6.png

 

but i have a lot of SSL anomaly in security events, more than 22,000 and sites are blocked; for example :

 

to website mask.apple-dns.net

Event Type : ssl-anomaly
Event Subtype : certificate-probe-failed

 

what can i do ?

 

thanks a lot

6 REPLIES 6
AEK
SuperUser
SuperUser

Hi

This is because mask.apple-dns.net on TCP 443 has no certificate.

AEK
AEK
mulbzh
New Contributor II

so what i have to do ?

AEK

But what are you trying to do? I see https;//mask.apple-dns.net is not a valid location (no Web server behind). So the question is why are you trying to access this location?

AEK
AEK
dingjerry_FTNT

Hi @mulbzh ,

 

If you test this website:

 

https://www.ssllabs.com/ssltest/analyze.html?d=mask.apple-dns.net

 

You will see that all the entries are failed.

 

Not sure what you need to do with this website, but you may add it to the SSL Inspection Exempt list.

Regards,

Jerry
mulbzh
New Contributor II

i have got many and many others erros like this :

7.png

 

also i can't do SSL exceptin, this option is only enable when SSL Deep inspection is selected

AEK
SuperUser
SuperUser

From your screenshot I tested the IP that have blocked sessions and all don't have a certificate, so SSL can't take place, just like for mask.apple-dns.net.

But still don't know what you are trying to do. Do you or your users have troubles using some applications?

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors