Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dirkdigs
New Contributor

ssl/ssh inspection breaking outlook

i enabled full ssl inspection in the default ssh/ssl policy and then outlook stopped working.
There is a problem with the proxy server' s certificate authority. Outlook is unable to connect to the proxy server mail.server.ca (Error Code 8)
It was suggested to do this by the fortigate when i went to Fortiview > Cloud Applications in my FortiOS 5.2
Full SSL inspection enabled for HTTPS in a SSL/SSH Inspection profile
any idea why?
3 REPLIES 3
Baptiste
Contributor II

I guess the certificate used by your Exchange server is replaced by the fortigate certificate with full ssl inspection

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
NeilG
Contributor

Exchange server uses mutual certificate auth, which prevents SSL inspection in general. http://technet.microsoft.com/en-us/library/dd439371(v=EXCHG.80).aspx
lunhas2k4
New Contributor III

Hi guys,

I suggest making a policy above the other policies without the ssl inspection with the specific destination of the server you want to get connection to.

 

That is what I did to resolve my issue.

Carlitos loves firewalls

NSE4 (5.4,6.0)

NSE5 (Fortimanager 6.0, Fortianalyzer 6.0)

NSE7 (Enterprise Firewall 6.0)

Carlitos loves firewalls NSE4 (5.4,6.0) NSE5 (Fortimanager 6.0, Fortianalyzer 6.0) NSE7 (Enterprise Firewall 6.0)
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors