Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Boris_Tolshew
New Contributor

Virtual server and SSL inspection

Do I still need to turn up "full deep ssl inspection" in FortiGate if ssl inspection already works in virtual server? I did some tests and it turned out that if we have Virtual Server (so FortiGate behaves like a reverse-proxy) and certificate inspection in Firewall Policy, FortiGate able to block FULL URL adresses. For example hxxps://gmail.com/assdasd/123.

In logs only with certificate inspection I see hxxps://gmail.com/assdasd/123 (not just hxxps://gmail.com). 

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Boris

Do you mean without deep inspection you can see and block a path/subdirectory, like example.com/abc/def?

Can you share screenshot of the firewall policy, VS config and the related logs?

AEK
AEK
Labels
Top Kudoed Authors