AnsweredHot!Weird Behaviour With SSL Inpection and Web Filtering?

Author
Guizado
New Member
  • Total Posts : 14
  • Scores: 0
  • Reward points: 0
  • Joined: 2017/04/20 07:53:01
  • Status: offline
2017/04/20 08:32:42 (permalink)
0

Weird Behaviour With SSL Inpection and Web Filtering?

Hello all,
I am having some issues with WEB Filtering and SSL Inspection / Deep Inspection.
So the first behaviour is, when using "Certificate Inspection" and "Inspect All Ports" IS NOT ticked, and I try to browse lets say a gambling site I get the "Web Page Blocked" splash screen by the Fortigate, so no problem, expected behaviour.
 
Now the same thing but with "Inspect All Ports" ticked and trying to browse the same website the Website is allowed.
 
 
Now lets try the same but with "Deep Inspection" instead of "Certificate Inspection"
Any options with "Inspect all Ports" enabled or disabled result on "This Page can't be displayed".

So Conclusion:
"Certificate Inspection":
Inspect All Ports Ticked = Gambling Page is not blocked, normal access to page.
Inspect all Ports is not Ticket and HTTPS = 443 = Fortigate Splash Screen "Web Page is Blocked" as Expected.
 
Deep Inpection: "This Page can't be displayed".

Finnally any sites I visit that are HTTP and not HTTPS I do get the Fortigate blocking Splash Screen.
 
Am I missing something is the behaviour normal?
 
Many Thanks
#1
hmtay_FTNT
Platinum Member
  • Total Posts : 228
  • Scores: 45
  • Reward points: 0
  • Joined: 2017/02/22 11:02:10
  • Status: offline
Re: Weird Behaviour With SSL Inpection and Web Filtering? 2017/04/21 08:26:37 (permalink) ☄ Helpfulby Guizado 2017/04/21 08:59:24
0
Hello Guizado,
 
Let's go through your case one by one:
 
>>Inspect All Ports Ticked = Gambling Page is not blocked, normal access to page.
Can I know which FortiOS are you using, there was a bug with Inspect All Ports with Proxy use.
 
>>Inspect all Ports is not Ticket and HTTPS = 443 = Fortigate Splash Screen "Web Page is Blocked" as Expected.
If you are doing certificate-inspection and you get a replacement message on a HTTPS site, that means you did import the SSL Certificate onto your trusted Root CA list correctly, am i right? If the replacement message page loads automatically, that means you most likely imported the certificate. If you got an error message first and had to click "Advanced", you most likely did not import the certificate.
 
>>Deep Inpection: "This Page can't be displayed".
If you imported the correct SSL Certificate, this should not happen.
 
Did you do something like this?
http://cookbook.fortinet.com/preventing-certificate-warnings/
 
HoMing
 
#2
Guizado
New Member
  • Total Posts : 14
  • Scores: 0
  • Reward points: 0
  • Joined: 2017/04/20 07:53:01
  • Status: offline
Re: Weird Behaviour With SSL Inpection and Web Filtering? 2017/04/21 08:37:08 (permalink)
0
Hello thanks for your reply.
 
The Certificate was created in the Fortinet, downloaded and signed by our Enterprise CA, and imported back, I am using this same certificate for "Certificate Inspection" and "Deep Inspection", the CA Server that signed the certificate is trusted on all our client Machines.
I am not getting any Certificate warnings, its either the page gets blocked properly, or a page cannot be displayed error as if I had no Internet gets displayed with Deep Inspection.
My version is 5.2.2 (642)
#3
hmtay_FTNT
Platinum Member
  • Total Posts : 228
  • Scores: 45
  • Reward points: 0
  • Joined: 2017/02/22 11:02:10
  • Status: offline
Re: Weird Behaviour With SSL Inpection and Web Filtering? 2017/04/21 08:52:29 (permalink) ☼ Best Answerby Guizado 2017/04/21 08:59:14
0
Hello Guizado,
 
Can you upgrade your FortiOS 5.2 to the latest 5.2 available? 5.2.2 is a very old version and there has been bug fixes on many features including deep-inspection.
 
https://info.fortinet.com/files/FortiOS/v5.00/images/build0670/fortios-v5.2.3-release-notes.pdf
 

265375 - In deep-inspection mode, the server certificate chain validation may not be handled correctly.
 
Unlike going from 5.2 to 5.4 or 5.6, you are unlikely to go through major updates. Getting the most updated FortiOS is important if you are using deep-inspection in proxy-mode - more so if you use Chrome. Chrome very frequently comes up with new cipher-suites and we have to add support for those cipher-suites. 
 
If you can give it a try and it still does not work, do let me know. 
 
HoMing
#4
Guizado
New Member
  • Total Posts : 14
  • Scores: 0
  • Reward points: 0
  • Joined: 2017/04/20 07:53:01
  • Status: offline
Re: Weird Behaviour With SSL Inpection and Web Filtering? 2017/04/21 08:59:10 (permalink)
0
Hello Thanks for your reply.
 
We have a Scheduled upgrade to the latest version 5.6 in about 3 weeks time, I will come back if we still experience any issues after the upgrade.
#5
a1dave23
New Member
  • Total Posts : 2
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/03/18 01:53:26
  • Status: offline
Re: Weird Behaviour With SSL Inpection and Web Filtering? 2019/04/02 07:27:53 (permalink)
0
Hi,
 
I am having this same issue, I am using the Fortigate self signed cert and it works for http sites but not https.
 
I am also not able to select a cert i have uploaded to the fortigate to use for a custom deep packet inspection.
 
Any help appreciated 
#6
Amalio C
New Member
  • Total Posts : 13
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/03/08 07:08:28
  • Location: FL
  • Status: offline
Re: Weird Behaviour With SSL Inpection and Web Filtering? 2019/04/24 13:53:32 (permalink)
0
Hello,
Did you find a solution for your second statement: "I am also not able to select a cert i have uploaded to the fortigate to use for a custom deep packet inspection." The thing is that I generate a CSR from my FortiGate, download it and signed by my root CA (which is installed on every corporate PC), but when I uploaded back to FirtiGate, it appeared on as a "Certificate", not as a "Local CA Certificate". 
And I uploaded it using Import > Local Certificate 
 
Did I do some wrong ? I'm using FortiOS 5.4
 
Thank you, 
#7
a1dave23
New Member
  • Total Posts : 2
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/03/18 01:53:26
  • Status: offline
Re: Weird Behaviour With SSL Inpection and Web Filtering? 2019/04/25 00:00:51 (permalink)
0
Hi, 
 
No we have not found a solution for this just yet. 
 
Regards  
#8
Amalio C
New Member
  • Total Posts : 13
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/03/08 07:08:28
  • Location: FL
  • Status: offline
Re: Weird Behaviour With SSL Inpection and Web Filtering? 2019/04/26 13:55:42 (permalink)
0
Check this link:
 https://stuff.purdon.ca/?page_id=155 
 
It was sent it to me by Fortigate support tech's
post edited by Amalio C - 2019/04/26 13:56:43
#9
Jump to:
© 2019 APG vNext Commercial Version 5.5