Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
clarkg
New Contributor

https sites issues

So We updated our Firmware to 5.0.9 not too long ago and we now seem to have issues with https sites. I just need to know if this behavior is normal, or if there is something wrong. The issues we have are that some https sites, not all, when users access them, they will come up with any or all of the following..... A blank white page The will state that there is no Java, or Flash installed, when there is. Or that the incorrect java or flash version is installed, even when we know for 100% sure that the correct version is on the pc. I can do one of 2 things to fix this. 1. I can either create an address object with the site url in it, and put it into a policy in front of our main user policy, that ONLY has AV and IPS turned on. SSL inspection and webcache are turned off in this policy. 2. I can put the url into the url filter the user gets as a wildcard and exempt, and that also makes the site work. Again, on our previous version of firmware, which I BELIEVE was 5.0.6 we didn' t seem to see this issue very often. However under the 5.0.6 firmware we were also having multiple issues with the url filter engine and ips engine and I believe the sslworker daemon crashing all the time. The firmware we are on now, 5.0.9 we do not have those issues. So I just need to know if these issues we are seeing now with https sites are normal behavior until the url is exempted, or if something else is going on. I have a ticket open with fortinet, just wanted to get some
1 Solution
Fullmoon

hope this help,got an issue with dropbox once ssl inspection was enabled in a policy.updated my version from 5.2.1 to 5.2.2 and do ssl exemptions. pls see attached file

Fortigate Newbie

View solution in original post

Fortigate Newbie
10 REPLIES 10
SteveRoadWarrior
New Contributor III

We just had to do something similar. 

 

Found an easy fix which kept it working for the rest of the internet sites:

- edit the web filter and enable web site filter

- add *.dropbox.com to the URL exemption list (chose wildcard)

 

see attached image

 

This allows the regular dropbox SSL Cert to be used for that site, but everything else has to be processed by the Fortigate.

 

Firmware is 5.0.11 - 80C

Labels
Top Kudoed Authors