We are using Fortigate 200d UTM, from few days back we are facing some issues regarding replacement messages, usually on user end when any web page gets block it shows my created replacement message with multiple details and reason such as client ip, server ip, user name, group name and category but now from few days all user getting only one message that "your connection is not private: or "There is a problem connecting securely to this website"
can any one please help me on this issue
It sounds like you have some type of SSL/SSH Profile enabled on your policies. If you have certificate inspection then they are visiting an SSL site that is blocked and the certificate your Fortigate is using to display this page is not trusted by your users. By not trusted I mean that the certificate is not their windows "Trusted Root Certification Authorities Store"
Yes you were right, i am getting replacement message on HTTP sites but not in HTTPS site.
i again regenerated certificate from domain controller certificate authority and import it on fortigate and install this same certificate on my pc but haven't receive replacement message on HTTPS sites
Did you install it under the Trusted Root CA list? Do you have a screenshot or can you show me the configuration? You can open a ticket with the TAC to get them to remotely connect to your network to help you out.
HoMing
One way to test if your case is as Eugene mentioned is to go to a HTTP website that is prohibited by the Web Filter and see if the replacement message shows up. If it does, then your settings are correct and the problem is with the SSL Certificate as mentioned.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.