I have a problem with the webfilter and app control of my Fortigate60E
I am blocking EVERYTHING that is remote access and it is not working, which it is but if I go to Log&Report>FowardTraffic absolutely NOTHING is reflected in "Application Name", which makes me assume that my traffic passes without SSL inspection.
I'm using a basic Monitoring setup profiel on App Control and Webfilter, and it doesn't work either, I don't really see anything.
You need to configure the policy with deep inspection .When using SSL Certificate Inspection, the SSL Handshake is not interrupted, but the FortiGate reads the CN part of the certificate. This CN part, has the URL for the certificate was signed to. This way, the FortiGate has an URL to check into its categories database. But the TLS/SSL content is not read in any way.
When you use deep inspection, the FortiGate impersonates the recipient of the originating SSL session, then decrypts and inspects the content to find threats and block them. It then re-encrypts the content and sends it to the real recipient.
After reviewing traffic flow diagram a bit and understanding that the IPS ENGINE encompasses all the traffic inspection(app control, webfilter, av, etc) , i realized that the ipsengine was not running in the "dig sys top",
so the restart was carried out through the CLI of ips process via " diagnose test application ipsengine 99".
Now you can see the inspection of packets through FG.
I was also able to notice that there was a crash:
273: 2022-01-24 10:51:29 ipsengine 07.000.044 crashed 3 times. The latest crash was at 2022-01-24
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.