hi
I have a server configured as a vip in my fortigate to be accesses from internet. I want to block it's admin page. (my.domain.com/admin) . I tried the policy with deep packet and ssl inspection along with creating a webfilter and blocked *\admin* but still admin page reachable from internet. how can i block admin page?
Solved! Go to Solution.
Hi @rezafathi ,
Please use the "Protecting SSL Server" option and install a valid server certificate on your FGT to decrypt and inspect traffic destined to the real server.
Created on ‎04-30-2025 12:21 AM Edited on ‎04-30-2025 12:21 AM
Hi
Hi @rezafathi ,
Please use the "Protecting SSL Server" option and install a valid server certificate on your FGT to decrypt and inspect traffic destined to the real server.
hi
thanks. should i do that for all vip servers or not?
I think that you can use one server certificate for multiple VIP servers.
what do you mean by server certificate? do you mean certificate for my domain?
thanks. will i have same security features as full ssl inspection when i use protecting ssl server?
Yes, technically, it is for inbound traffic from the Internet with "protecting ssl server". And the other option is for outbound traffic to the Internet.
Both have the same features.
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.