Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tuan2tech
New Contributor III

Why is Fortinet blocking SSL connections to iCloud-related domains?

Hi everyone,

I'm seeing multiple denied SSL connections in my FortiGate logs, and I can't figure out exactly why this is happening or whether it's necessary to keep blocking them.

 

SSL.jpg

6 REPLIES 6
AEK
SuperUser
SuperUser

Hi Tuan

Your logs show UTM Blocked. That means in the policy that is blocking this traffic there some security profile (App Ctrl or Web Filter) denying this traffic.

AEK
AEK
tuan2tech
New Contributor III

According to the image, it is being blocked under the "Network Services" category, but I haven't blocked anything.DNS.jpg

AEK
SuperUser
SuperUser

Please double click on the related log entry, on the right pan open the Security tab, there you should find more information on what blocked the traffic.

AEK
AEK
nweckel
Staff
Staff

Hello @tuan2tech 

You can also check in Security Events logs for WebFilter, Application control, SSL... depending on which UTM profiles you have configured in firewall policy LAN to WAN. 

primadeluxe
New Contributor

Same issue here..

Rino_B
New Contributor III

Possibly it is an SSL block with event subtype certificate-probe-failed? Please check: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-fix-SSL-connection-is-blocked...

Rino_B - FCS
Rino_B - FCS
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors