Hi everyone,
I'm seeing multiple denied SSL connections in my FortiGate logs, and I can't figure out exactly why this is happening or whether it's necessary to keep blocking them.
Hi Tuan
Your logs show UTM Blocked. That means in the policy that is blocking this traffic there some security profile (App Ctrl or Web Filter) denying this traffic.
According to the image, it is being blocked under the "Network Services" category, but I haven't blocked anything.
Please double click on the related log entry, on the right pan open the Security tab, there you should find more information on what blocked the traffic.
Hello @tuan2tech
You can also check in Security Events logs for WebFilter, Application control, SSL... depending on which UTM profiles you have configured in firewall policy LAN to WAN.
Same issue here..
Possibly it is an SSL block with event subtype certificate-probe-failed? Please check: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-fix-SSL-connection-is-blocked...
User | Count |
---|---|
2403 | |
1296 | |
778 | |
541 | |
454 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.