FCP_FGT_AD-7.6 · Question #75
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites…
The correct answer is A. The browser does not trust the certificate used by FortiGate for SSL inspection. When full SSL inspection is enabled, FortiGate acts as a man-in-the-middle: it decrypts HTTPS traffic, inspects it, then re-encrypts it using a dynamically generated certificate signed by FortiGate's own CA certificate. If this CA certificate has not been imported into the…
Question
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors. What is the reason for the certificate warning errors?
Options
- AThe browser does not trust the certificate used by FortiGate for SSL inspection.
- BThe option invalid SSL certificates is set to allow on the SSL/SSH inspection profile
- CThe matching firewall policy is set to proxy inspection mode.
- DThe certificate used by FortiGate for SSL inspection does not contain the required certificate
How the community answered
(57 responses)- A89% (51)
- B2% (1)
- C7% (4)
- D2% (1)
Explanation
When full SSL inspection is enabled, FortiGate acts as a man-in-the-middle: it decrypts HTTPS traffic, inspects it, then re-encrypts it using a dynamically generated certificate signed by FortiGate's own CA certificate. If this CA certificate has not been imported into the browser's or operating system's trusted certificate store, the browser will not recognize FortiGate's CA as a trusted authority and will display certificate warnings for every HTTPS site. HTTP sites are not affected because no TLS certificate is involved. The fix is to export the FortiGate CA certificate and distribute it to all endpoints as a trusted root CA, either manually or via Group Policy.
Topics
Community Discussion
No community discussion yet for this question.