A real-life situation
Nearly all web traffic is HTTPS. FGT1 has antivirus and IPS on the Internet policy, but a test download of the EICAR test file over HTTPS isn't blocked, while the same file over plain HTTP is. Nothing is broken: with certificate inspection the FortiGate never sees the file, only the encrypted stream.
Two levels of inspection
| Certificate inspection | Deep inspection | |
|---|---|---|
| Decrypts? | No | Yes |
| Sees | Server name (SNI) and certificate | Full URLs, pages, files, application data |
| Web filter | By domain category | By full URL, plus content features |
| AV, IPS, app control | Very limited on HTTPS | Full |
| Client changes | None | Clients must trust the FortiGate CA |
How deep inspection works
- TLS to www.example.com, please.ClientHello from PC1 to FGT1.ClientHello
- FGT1 ↔ serverFGT1 opens its own TLS session to www.example.com and validates the real certificate.
- Certificatewww.example.com, signed by the FortiGate CA (a copy made on the fly).Certificate from FGT1 to PC1.
- Client checkPC1 trusts the FortiGate CA, so the certificate is accepted. If it didn't, the browser would show a warning.
- Request and download, encrypted to FGT1, decrypted and inspected, then re-encrypted to the server.HTTPS data from PC1 to FGT1.HTTPS data
Configure deep inspection
Edit SSL/SSH Inspection Profile: Staff-Deep
- Inspection method
- SSL Certificate Inspection Full SSL Inspection
- CA certificate
- Fortinet_CA_SSLEvery client must trust this CA.
- Invalid certificates
- Allow Block
- Web categories
- Finance and Banking Health and Wellness
- Addresses
- Pinned-Apps
- Reputable websites
- Off
Exempt from SSL Inspection
config firewall policy
edit 3
set ssl-ssh-profile "Staff-Deep"
next
endCreate the profile by cloning the built-in deep-inspection profile, then select it on the policy. Roll it out to a pilot group first.
Making clients trust the CA
- Download the CA certificate from the profile page (or use a subordinate CA from your own PKI).
- Install it as a trusted root on managed devices with Group Policy, an MDM or your endpoint tool.
- Remember applications with their own certificate store (some browsers, Java, developer tools) and guest devices you don't manage: exempt them or don't deep-inspect them.
Exemptions
Exempt traffic that must not or cannot be decrypted: banking and health sites for privacy, apps that pin certificates (some update services and mobile apps), and sites that use client certificates. FortiOS includes a default exemption list of well-known services; review it and add your own.
Inbound: protecting your own server
For traffic to WEB1, there is no need to forge certificates: upload WEB1's real certificate and key to an SSL inspection profile with "Protecting SSL Server", and use it on the Internet-to-WEB1 policy. IPS can then inspect attacks hidden inside HTTPS.
Why it works this way
TLS is designed to stop anyone in the middle reading traffic, and it succeeds. The only way to inspect it is to become a party to the session that the client trusts. That is why deep inspection needs a trusted CA on every client, and why it has privacy, legal and compatibility costs that certificate inspection doesn't.
Common mistakes
- Enabling deep inspection before the CA is deployed: every HTTPS site shows a certificate warning.
- Allowing invalid certificates, so users can't tell a real attack from inspection.
- Not exempting pinned applications, which then fail with vague connection errors.
- Expecting AV and IPS to protect HTTPS traffic under certificate inspection.
Key takeaways
- Certificate inspection reads SNI and the certificate; deep inspection decrypts and re-encrypts.
- Deep inspection needs the FortiGate CA (or your own subordinate CA) trusted on every client.
- Exempt privacy-sensitive categories and pinned apps.
- Inbound to your own server, inspect with the server's real certificate.
Check yourself
After switching to deep inspection, every HTTPS site shows a certificate warning. What is wrong?
Which can certificate inspection still do for HTTPS?
A mobile banking app stops working after deep inspection is enabled. Most likely?