Description This article describes the requirements of a Server
Certificate in an SSL Inspection profile while selecting 'Protecting SSL
Server'. Scope FortiGate. Solution When creating or editing an SSL
Inspection profile, and selecting 'Protecting ...
Description This article describes one scenario (GRE + IPSec) that is
unsupported for NP7 offloading. Scope FortiGate. Solution NP7 offloading
supports the GRE tunnel, including terminating on FortiGate or passing
through FortiGate.NP7 offloading sup...
Description This article explains the behavior of 'Inspect All' in an
SSL/SSH inspection profile. Scope FortiProxy. Solution When creating or
editing an SSL/SSH inspection profile, there is an option called
'Inspect All'. Full SSL Inspection: Perform...
Description This article describes the 'Default Device Selection for
Install' option in ADOM settings while creating or editing one ADOM on
FortiManager. Scope FortiManager. Solution When creating or editing one
ADOM on FortiManager, there is an opti...
Description This article describes how to display images on the a Web
Filter Block page. Scope FortiGate. Solution Images can be added to the
Web Filter Block Replacement Message with the Replacement Message tag
'%%IMAGE:%%'. When the URL is blocked ...
Hi @AC_CHANGE , 1) Please share the configuration of the address object
"IPSec_VPN_Delta_split". You may also have to ensure this object covers
all the VLAN subnets. 2) You need to run the "diag sniffer packet" and
the "debug flow" commands to collec...
Hi @mulbzh , If you test this website:
https://www.ssllabs.com/ssltest/analyze.html?d=mask.apple-dns.net You
will see that all the entries are failed. Not sure what you need to do
with this website, but you may add it to the SSL Inspection Exempt lis...
Hi @IrbkOrrum , The wildcard FQDN resolution depends on the DNS traffic
passing through FGT. So if there is no relevant DNS traffic passing
through FGT, FGT may not get the correct IPs. You may try with ISDB. You
may check the following article about...