Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
hope this help,got an issue with dropbox once ssl inspection was enabled in a policy.updated my version from 5.2.1 to 5.2.2 and do ssl exemptions. pls see attached file
Fortigate Newbie
Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
I AM currently on 5.0.9 and having these issues. Is it a good idea to downgrade to 5.0.7? Turning off the ssl inspection seems to make the problems go away.
billp wrote:
Clark, I can report some oddities with the SSL/SSH Inspection policy. If I inspect port 443, it will prevent my Skype clients from logging in. I posted about this earlier, but I seem to be alone with this problem based on the responses. You might try turning off your SSL/SSH Inspection policy to see if it fixes the problems you' re seeing. I am currently on firmware 5.0.7, but am considering jumping to 5.0.9 soon so that I have the benefit of the latest bug fixes. If you are using 5.0.6, you probably want to jump to at least 5.0.7 because of the heartbleed issues with earlier versions.
With deep SSL inspection there are certain programs/apps which will not work. When visiting HTTPS websites with a browser you can either continue through the certificate warning or import the cert/CA into the browser... Programs like Skype are looking for specific client/server certificates so deep SSL inspection will never work with these.
We have the cert imported into the browser. The fortigate cert. I am not having skype issues. I am having issues with regular https websites giving random results.
Bromont wrote:With deep SSL inspection there are certain programs/apps which will not work. When visiting HTTPS websites with a browser you can either continue through the certificate warning or import the cert/CA into the browser... Programs like Skype are looking for specific client/server certificates so deep SSL inspection will never work with these.
clarkg wrote:We have the cert imported into the browser. The fortigate cert. I am not having skype issues. I am having issues with regular https websites giving random results.
On your web filter profile, which of the following options are set...
Can you give an example of web sites giving you trouble?
If Security log events are enabled on the firewall policy, are you seeing any blocked sites in the security/Web filter logs?
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Full SSL inspection is still very shaky. We are on 5.2.1 version and SSL inspect work for a certain vendors and doesn't work for other. In our case, whenever we enable full SSL Inpsect, Microsoft Office365 mail stop connecting and LYNC, Gotomeeting,Webex group sharing stop work. It work perfectly with only SSL certificate inspection but does not work with full SSL inspection.
As stated before it can't work for applications which require a specific certificate (certificate pinning)
Phuoc Ngo wrote:I have same your version, i have problem with much sites, major with sites that redirect from http to https. Then i cant configure new account office365 in outlook client, meanwhile work fine account already configure. In my fortigate i cant disabled SSL inspection if i not disabled webfilter before. I try build dedicated rules but seems not work, i can only enable category in webfilter so sites works fine. I try create excemption in web filter but seems ignore if category is set to blocked. I havant idea to solve problem. You ? Have found solution ? Thanks M.
Full SSL inspection is still very shaky. We are on 5.2.1 version and SSL inspect work for a certain vendors and doesn't work for other. In our case, whenever we enable full SSL Inpsect, Microsoft Office365 mail stop connecting and LYNC, Gotomeeting,Webex group sharing stop work. It work perfectly with only SSL certificate inspection but does not work with full SSL inspection.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1731 | |
1098 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.