Fortinet black logo

Cookbook

Configuring full SSL inspection

Copy Link
Copy Doc ID 23809264-eafe-11eb-97f7-00505692583a:537506
Download PDF

Configuring full SSL inspection

To configure full SSL inspection:
  1. Go to Security Profiles > SSL/SSH Inspection, and create a new profile.
  2. Enter a Name, select the certificate from the CA Certificate dropdown menu, and make sure Inspection Method is set to Full SSL Inspection.

  3. Add the certificate to your web browser's list of trusted certificates. End users will likely see certificate warnings unless the certificate is installed in their browser.
  4. Next go to Policy & Objects > IPv4 Policy and edit the policy that allows Internet access.

    Under Security Profiles, enable SSL/SSH Inspection and select the custom profile created earlier.

    Enable Application Control and set it to default.

Configuring full SSL inspection

To configure full SSL inspection:
  1. Go to Security Profiles > SSL/SSH Inspection, and create a new profile.
  2. Enter a Name, select the certificate from the CA Certificate dropdown menu, and make sure Inspection Method is set to Full SSL Inspection.

  3. Add the certificate to your web browser's list of trusted certificates. End users will likely see certificate warnings unless the certificate is installed in their browser.
  4. Next go to Policy & Objects > IPv4 Policy and edit the policy that allows Internet access.

    Under Security Profiles, enable SSL/SSH Inspection and select the custom profile created earlier.

    Enable Application Control and set it to default.