hi all,
so i'm trying to solve this issue for the last few days.
first i have imported my server certificate onto my fortigate unit as local certificate (public+private).
second i activated ssl-inspection profile with the option "protecting a server" which i understand means replace certificate instad of resign
and last i have activated that profile on my inbound traffic (VIP->SERVER HTTPS).
now when someone try to access that certifiace it fails most of the time beacuse it seems the PKI chain is broken.
i also installed the subordiante CA (go daddy g2 CA) on my unit as external ca with the same results.
seems i found my problem.
AV on proxy mode (on the same policy) did all the truble.
flow mode works fine.
seems its listed as a bug on 5.4 release notes (bug ID 304432)
User | Count |
---|---|
2548 | |
1354 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.