Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Boris_Tolshew
New Contributor

Virtual server and SSL inspection

Do I still need to turn up "full deep ssl inspection" in FortiGate if ssl inspection already works in virtual server? I did some tests and it turned out that if we have Virtual Server (so FortiGate behaves like a reverse-proxy) and certificate inspection in Firewall Policy, FortiGate able to block FULL URL adresses. For example hxxps://gmail.com/assdasd/123.

In logs only with certificate inspection I see hxxps://gmail.com/assdasd/123 (not just hxxps://gmail.com). 

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Boris

Do you mean without deep inspection you can see and block a path/subdirectory, like example.com/abc/def?

Can you share screenshot of the firewall policy, VS config and the related logs?

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors