Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jond
New Contributor III

"It looks like xyz.com closed the connection" with SSL Deep inspection enabled

Hi All,

 


I'm getting a lot of help desk tickets with stuff like "It looks like mathsbot.com closed the connection" (one of many sites!)  I use deep packet inspection.

 

I've tried pretty much every option on the profile to change that, but the only thing that seems to work is adding the site (or the relevant category) to the SSL exceptions.  I'm getting enough of these tickets for it not to be sustainable.

 

Any ideas anyone? (I do need DPI, educational institutions)


Cheers


Jon

#fortigate

10 REPLIES 10
AEK
SuperUser
SuperUser

Hi Jon

Which FortiOS version?

AEK
AEK
Jond
New Contributor III

Hi there,

 

v7.2.8 build1639

 

Cheers

 

Jon

kaurm
Staff
Staff

Hello Jon,
What is the inspection mode used on the policy , please provide complete screenshot of the error.

Thanks

Jond
New Contributor III

Inspection mode is Proxy.

 

The error message is exactly what I put - "It looks like xyz.com closed the connection" (with a Edge graphic or similar)

 

Cheers


Jon

sjoshi
Staff
Staff

To address the issue of frequent help desk tickets related to sites like "mathsbot.com" closing the connection despite using deep packet inspection, consider creating a custom SSL/TLS inspection profile where you selectively exempt specific categories or websites prone to such issues, ensuring a balance between security and usability for educational institutions. This approach can help reduce the number of tickets while maintaining the necessary level of security.

Let us know if this helps.
Salon Raj Joshi
Jond
New Contributor III

Thanks Salon Raj Joshi

 

I'm getting this too frequently to do it for every site or category.  I'll end up exempting all the sites that I'm wanting to look at from a DPI perspective.

sjoshi

any specific error you are getting in SSL event logs on FGT

Let us know if this helps.
Salon Raj Joshi
callmeahero
New Contributor II

SSL Deep Inspection can break certain websites, especially if they use non-standard SSL/TLS configurations.

 

The DPI feature inspects and re-encrypts traffic, which some sites might not support, causing the connection to fail.

 

While adding sites or categories to the SSL exceptions list works, it’s not ideal if you have a lot of sites.

 

However, exceptions might be necessary for websites that don’t work well with DPI.

 

Instead of adding many sites to exceptions, consider creating custom DPI profiles that allow more flexibility.

 

For example, you can disable certain checks like SSL certificate validation for specific sites or only apply DPI to certain traffic types.

 

If the issues are widespread and affecting many users, you might also want to check the SSL Forward Proxy settings.

 

This can help reduce issues with SSL decryption by managing the way certificates are handled.

 

You can review the logs to identify which sites or categories are causing the most issues.

 

Based on this, you might be able to fine-tune DPI settings to avoid interruptions.

AEK
SuperUser
SuperUser

Can you share the cli config of the related ssl inspection profile?

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors