Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jase888
New Contributor

HTTPS Sites dont show block correctly

If a user goes to a HTTPS site it doesnt automatically come up with a Fortigate blocked this website warning. The user has to click the site not secure warning then it shows it. Is there something I haven't setup correct?

 

 

1 REPLY 1
sw2090
Honored Contributor

That looks like if you are usng the Fortinet defaultcertificate or some other Certifacte Authority that is not trusted by browsers per default.

To inspect and block https you must do somewhat man in the middle. You need to decrypt traffic look at it and recrypt it to deliver it. And you cannot do that with the certificate origninally used because you don't have the key.

Also if the blocking page is delivered via https the FortiGate will have to crypt it with a certificate. 

So you either need to install a trusted certificate onto your Fortigate to use it for encryption or you have to make your browser trust the existing one.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors