Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Joe2
New Contributor II

Is SSL inspection required for Intrusion Prevention System to analyze encrypted traffic?

Hi,

 

We are only enabling IPS on some firewall policies and I want to verify if SSL inspection is required for IPS to analyze encrypted traffic? Or is IPS capable of performing deep packet inspection without SSL inspection?

 

I am a bit confused, because the below Fortinet link, mentions: "FortiGate IPS is even capable of performing deep packet inspection to scan encrypted payloads in order to detect and prevent threats from attackers."

Also, that same link mentions: "Secure sockets layer (SSL) content scanning and inspection allows you to apply antivirus scanning, web filtering, and email filtering to encrypted traffic. You can apply SSL inspection profiles to firewall policies." - No mention for IPS.

Reference Link: https://docs.fortinet.com/document/fortigate/6.2.14/cookbook/565562/intrusion-prevention

 

Whereas the best practice section for IPS in the NSE4 version 7.2 Security Guide (Page 410) mentions: "Certain vulnerabilities apply only to encrypted connections. In some of these cases, FortiGate can't identify the threat reliably if it can't parse the payload. Fort his reason, you must use an SSL inspection profile if you want to maximum benefit from your IPS."

 

Thanks,

2 Solutions
rosatechnocrat
Contributor II

@Joe2 : Yeah that's correct... IPS requires SSL Deep inspection if you want to analyze or protect all traffic.  If there is no SSL Deep packet inspection then https packets or encrypted traffic will not be able to decrypt and might miss IPS analysis. 

Rosa Technocrat -- Also on YouTube---Please do Subscribe

View solution in original post

Rosa Technocrat -- Also on YouTube---Please do Subscribe
pavankr5
Staff
Staff

for the IPS to analyze encrypted traffic, SSL inspection is required. Because SSL encryption is designed to prevent eavesdropping on the content of communications, including potential threats. Without SSL inspection, the IPS would not be able to see the contents of the encrypted traffic, which could potentially hide malicious activity.

It is possible for some IPS systems to perform deep packet inspection without SSL inspection, by using other techniques such as heuristic scanning.

Using SSL inspection profiles in conjunction with IPS is generally recommended for maximum security effectiveness.

View solution in original post

4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello Joe,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
rosatechnocrat
Contributor II

@Joe2 : Yeah that's correct... IPS requires SSL Deep inspection if you want to analyze or protect all traffic.  If there is no SSL Deep packet inspection then https packets or encrypted traffic will not be able to decrypt and might miss IPS analysis. 

Rosa Technocrat -- Also on YouTube---Please do Subscribe
Rosa Technocrat -- Also on YouTube---Please do Subscribe
pavankr5
Staff
Staff

for the IPS to analyze encrypted traffic, SSL inspection is required. Because SSL encryption is designed to prevent eavesdropping on the content of communications, including potential threats. Without SSL inspection, the IPS would not be able to see the contents of the encrypted traffic, which could potentially hide malicious activity.

It is possible for some IPS systems to perform deep packet inspection without SSL inspection, by using other techniques such as heuristic scanning.

Using SSL inspection profiles in conjunction with IPS is generally recommended for maximum security effectiveness.

Joe2
New Contributor II

Thank you!

Labels
Top Kudoed Authors