Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
clarkg
New Contributor

https sites issues

So We updated our Firmware to 5.0.9 not too long ago and we now seem to have issues with https sites. I just need to know if this behavior is normal, or if there is something wrong. The issues we have are that some https sites, not all, when users access them, they will come up with any or all of the following..... A blank white page The will state that there is no Java, or Flash installed, when there is. Or that the incorrect java or flash version is installed, even when we know for 100% sure that the correct version is on the pc. I can do one of 2 things to fix this. 1. I can either create an address object with the site url in it, and put it into a policy in front of our main user policy, that ONLY has AV and IPS turned on. SSL inspection and webcache are turned off in this policy. 2. I can put the url into the url filter the user gets as a wildcard and exempt, and that also makes the site work. Again, on our previous version of firmware, which I BELIEVE was 5.0.6 we didn' t seem to see this issue very often. However under the 5.0.6 firmware we were also having multiple issues with the url filter engine and ips engine and I believe the sslworker daemon crashing all the time. The firmware we are on now, 5.0.9 we do not have those issues. So I just need to know if these issues we are seeing now with https sites are normal behavior until the url is exempted, or if something else is going on. I have a ticket open with fortinet, just wanted to get some
1 Solution
Fullmoon

hope this help,got an issue with dropbox once ssl inspection was enabled in a policy.updated my version from 5.2.1 to 5.2.2 and do ssl exemptions. pls see attached file

Fortigate Newbie

View solution in original post

Fortigate Newbie
10 REPLIES 10
billp
Contributor

Clark, I can report some oddities with the SSL/SSH Inspection policy. If I inspect port 443, it will prevent my Skype clients from logging in. I posted about this earlier, but I seem to be alone with this problem based on the responses. You might try turning off your SSL/SSH Inspection policy to see if it fixes the problems you' re seeing. I am currently on firmware 5.0.7, but am considering jumping to 5.0.9 soon so that I have the benefit of the latest bug fixes. If you are using 5.0.6, you probably want to jump to at least 5.0.7 because of the heartbleed issues with earlier versions.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
clarkg
New Contributor

I AM currently on 5.0.9 and having these issues.  Is it a good idea to downgrade to 5.0.7?  Turning off the ssl inspection seems to make the problems go away.  

 

billp wrote:
Clark, I can report some oddities with the SSL/SSH Inspection policy. If I inspect port 443, it will prevent my Skype clients from logging in. I posted about this earlier, but I seem to be alone with this problem based on the responses. You might try turning off your SSL/SSH Inspection policy to see if it fixes the problems you' re seeing. I am currently on firmware 5.0.7, but am considering jumping to 5.0.9 soon so that I have the benefit of the latest bug fixes. If you are using 5.0.6, you probably want to jump to at least 5.0.7 because of the heartbleed issues with earlier versions.

Bromont_FTNT

With deep SSL inspection there are certain programs/apps which will not work. When visiting HTTPS websites with a browser you can either continue through the certificate warning or import the cert/CA into the browser... Programs like Skype are looking for specific client/server certificates so deep SSL inspection will never work with these.

clarkg

We have the cert imported into the browser.  The fortigate cert.   I am not having skype issues.  I am having issues with regular https websites giving random results.

 

Bromont wrote:

With deep SSL inspection there are certain programs/apps which will not work. When visiting HTTPS websites with a browser you can either continue through the certificate warning or import the cert/CA into the browser... Programs like Skype are looking for specific client/server certificates so deep SSL inspection will never work with these.

Dave_Hall
Honored Contributor

clarkg wrote:

We have the cert imported into the browser.  The fortigate cert.   I am not having skype issues.  I am having issues with regular https websites giving random results.

 

On your web filter profile, which of the following options are set...

 

Can you give an example of web sites giving you trouble? 

 

If Security log events are enabled on the firewall policy, are you seeing any blocked sites in the security/Web filter logs?

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Phuoc_Ngo
New Contributor

Full SSL inspection is still very shaky.  We are on 5.2.1 version and SSL inspect work for a certain vendors and doesn't work for other.  In our case, whenever we enable full SSL Inpsect, Microsoft Office365 mail stop connecting and LYNC, Gotomeeting,Webex group sharing stop work.  It work perfectly with only SSL certificate inspection but does not work with full SSL inspection. 

Bromont_FTNT

As stated before it can't work for applications which require a specific certificate (certificate pinning)

amatteo78

Phuoc Ngo wrote:
Full SSL inspection is still very shaky.  We are on 5.2.1 version and SSL inspect work for a certain vendors and doesn't work for other.  In our case, whenever we enable full SSL Inpsect, Microsoft Office365 mail stop connecting and LYNC, Gotomeeting,Webex group sharing stop work.  It work perfectly with only SSL certificate inspection but does not work with full SSL inspection. 
I have same your version, i have problem with much sites, major with sites that redirect from http to https. Then i cant configure new account office365 in outlook client, meanwhile work fine account already configure. In my fortigate i cant disabled SSL inspection if i not disabled webfilter before. I try build dedicated rules but seems not work, i can only enable category in webfilter so sites works fine. I try create excemption in web filter but seems ignore if category is set to blocked. I havant idea to solve problem. You ? Have found solution ? Thanks M.
Fullmoon

hope this help,got an issue with dropbox once ssl inspection was enabled in a policy.updated my version from 5.2.1 to 5.2.2 and do ssl exemptions. pls see attached file

Fortigate Newbie

Fortigate Newbie
Top Kudoed Authors