{"id":1413,"date":"2026-09-10T21:17:49","date_gmt":"2026-09-10T15:47:49","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/"},"modified":"2026-09-30T14:57:40","modified_gmt":"2026-09-30T09:27:40","slug":"fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/","title":{"rendered":"FortiGate SSL Deep Inspection: Design, Configuration and Troubleshooting"},"content":{"rendered":"<p>Modern enterprise web traffic is almost entirely encrypted using Transport Layer Security (TLS). While this protects data privacy, it creates a massive operational blind spot for security teams. Cyberattacks, malware command-and-control communications, and data exfiltration techniques routinely hide behind valid TLS encryption. <strong>FortiGate SSL deep inspection<\/strong> addresses this challenge by decrypting, inspecting, and re-encrypting network traffic in real time. This process allows deep security profiles like Antivirus, Intrusion Prevention System (IPS), Web Filtering, and Application Control to inspect payload contents that would otherwise pass through completely unmonitored.<\/p>\n<p>Implementing full TLS decryption requires precise architectural planning, active certificate management, and operational safeguards. This technical tutorial covers the design, step-by-step configuration, traffic processing, and systematic troubleshooting workflow required to deploy deep inspection safely in enterprise environments.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>An enterprise organization wants to secure outbound internet access for its corporate workstations. The organization must enforce strict threat prevention profiles against malware and unauthorized data leaks. However, the security team faces three primary constraints:<\/p>\n<ul>\n<li><strong>Visibility:<\/strong> Security profiles must inspect HTTPS traffic to detect payloads and URL parameters.<\/li>\n<li><strong>Privacy &amp; Compliance:<\/strong> Sensitive site categories\u2014specifically <em>Finance and Banking<\/em> and <em>Health and Wellness<\/em>\u2014must be excluded from decryption to comply with privacy laws.<\/li>\n<li><strong>Operational Stability:<\/strong> Applications that enforce Certificate Pinning (such as Microsoft Teams, Zoom, and cloud storage agents) must not break when deep inspection is enabled.<\/li>\n<\/ul>\n<p>To satisfy these requirements, the engineering team will deploy a custom Subordinate Certificate Authority (CA) on the FortiGate, distribute the issuing certificate to all endpoints via Active Directory Group Policy (GPO), and configure a FortiGate SSL deep inspection profile with targeted exemptions.<\/p>\n<h2>Lab Topology<\/h2>\n<p>The following diagram illustrates the network path between the internal endpoint, the FortiGate firewalls performing Man-in-the-Middle (MITM) decryption, and the destination web server on the public internet.<\/p>\n<pre>\n+--------------------------------+\n|  Corporate Endpoint (Client)   |\n|  IP: 192.0.2.50                |\n|  Trusts: Enterprise Sub-CA     |\n+---------------+----------------+\n                |\n                | [HTTPS Port 443]\n                v\n+---------------+----------------+\n|  FortiGate Next-Gen Firewall   |\n|  Interface port2: 192.0.2.1    |  &lt;--- Intercepts TLS Session\n|  Interface port1: 198.51.100.2 |   Re-encrypted Session]\n                v\n+---------------+----------------+\n|  Internet \/ Remote Web Server  |\n|  IP: 203.0.113.50              |\n+--------------------------------+\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>The network parameters and FortiOS configuration objects used in this tutorial are detailed in the table below. Note that production deployment values must be adapted to your specific IP addressing scheme and PKI hierarchy.<\/p>\n<table>\n<thead>\n<tr>\n<th>Object Type<\/th>\n<th>Object \/ Name<\/th>\n<th>Value \/ Configuration Detail<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>LAN Interface<\/td>\n<td>port2<\/td>\n<td>192.0.2.1\/24<\/td>\n<\/tr>\n<tr>\n<td>WAN Interface<\/td>\n<td>port1<\/td>\n<td>198.51.100.2\/24 (Gateway: 198.51.100.1)<\/td>\n<\/tr>\n<tr>\n<td>Internal Subnet<\/td>\n<td>CORP_LAN_192.0.2.0_24<\/td>\n<td>192.0.2.0\/255.255.255.0<\/td>\n<\/tr>\n<tr>\n<td>External Target IP<\/td>\n<td>LAB_WEB_SERVER<\/td>\n<td>203.0.113.50<\/td>\n<\/tr>\n<tr>\n<td>CA Certificate<\/td>\n<td>Enterprise_SubCA<\/td>\n<td>Subordinate CA Key\/Cert Pair signed by Internal PKI<\/td>\n<\/tr>\n<tr>\n<td>SSL\/SSH Profile<\/td>\n<td>Deep_Inspection_Enterprise<\/td>\n<td>Custom Deep Inspection Profile with selective exemptions<\/td>\n<\/tr>\n<tr>\n<td>Firewall Policy<\/td>\n<td>Outbound_Corporate_Access<\/td>\n<td>Policy ID 10 (port2 -&gt; port1) with UTM profiles enabled<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<p>Before configuring FortiGate SSL deep inspection, ensure that the following baseline requirements are met in your environment:<\/p>\n<ul>\n<li><strong>Active Directory PKI \/ Private CA:<\/strong> You need an Enterprise Root or Intermediate Certificate Authority capable of issuing an Subordinate CA certificate with Key Usage set to <code>Digital Signature<\/code>, <code>Certificate Signing<\/code>, and <code>CRL Signing<\/code>.<\/li>\n<li><strong>Certificate Deployment:<\/strong> The Root CA and any Intermediate CAs must be pre-installed in the Trusted Root Certification Authorities store on all managed endpoints. Unmanaged or personal devices (BYOD) will receive browser certificate warnings if this trust anchor is missing.<\/li>\n<li><strong>FortiOS Baseline:<\/strong> This guide targets FortiOS version 7.0 and higher. Note that interface layouts and GUI options can vary slightly across hardware models and release branches.<\/li>\n<li><strong>Hardware Offloading Awareness:<\/strong> Content inspection switches processing from network processors (NP) to content processors (CP9\/CP10) or software SSL engines. Ensure CPU overhead is factored into firewall capacity planning.<\/li>\n<\/ul>\n<h2>Step-by-Step GUI Configuration<\/h2>\n<h3>Step 1: Import the Subordinate CA Certificate<\/h3>\n<p>To inspect encrypted sessions without causing untrusted certificate warnings, the FortiGate must sign generated site certificates on the fly using a certificate trusted by clients.<\/p>\n<ol>\n<li>Log in to the FortiGate administrative GUI.<\/li>\n<li>Navigate to <strong>System &gt; Certificates<\/strong>. <em>(Note: If Certificates is not visible, enable it under <strong>System &gt; Feature Visibility &gt; Certificates<\/strong>).<\/em><\/li>\n<li>Click <strong>Import &gt; Local Certificate<\/strong>.<\/li>\n<li>Select <strong>Certificate<\/strong> as the import type, upload the PKCS#12 (<code>.pfx<\/code> or <code>.p12<\/code>) file containing the Subordinate CA private key and certificate, and enter the password.<\/li>\n<li>Verify that the imported certificate status displays as <code>OK<\/code> and lists appropriate usage permissions. Rename the certificate object to <code>Enterprise_SubCA<\/code> for clarity.<\/li>\n<\/ol>\n<h3>Step 2: Create the SSL\/SSH Inspection Profile<\/h3>\n<p>Now, construct the custom inspection profile to define how HTTPS traffic is handled, exempted, or blocked.<\/p>\n<ol>\n<li>Navigate to <strong>Security Profiles &gt; SSL\/SSH Inspection<\/strong>.<\/li>\n<li>Click <strong>Create New<\/strong> in the top menu.<\/li>\n<li>Set the <strong>Name<\/strong> to <code>Deep_Inspection_Enterprise<\/code>.<\/li>\n<li>Under <strong>SSL Inspection Options<\/strong>, set the <strong>Inspection Method<\/strong> to <strong>Full Inspection<\/strong> (or <em>Deep Inspection<\/em> depending on FortiOS release).<\/li>\n<li>Set the <strong>CA Certificate<\/strong> dropdown to your imported certificate: <code>Enterprise_SubCA<\/code>.<\/li>\n<li>Configure the protocol settings for <strong>HTTPS<\/strong>:\n<ul>\n<li><strong>Inspect All Ports:<\/strong> Enabled (or specify target port 443).<\/li>\n<li><strong>Untrusted SSL Certificates:<\/strong> Select <strong>Block<\/strong> to protect internal endpoints from expired or invalid external certificates.<\/li>\n<\/ul>\n<\/li>\n<li>Under <strong>Exempt from SSL Inspection<\/strong>, toggle <strong>URL Category<\/strong> to <code>Enable<\/code>. Select categories to bypass, such as <code>Finance and Banking<\/code> and <code>Health and Wellness<\/code>.<\/li>\n<li>Toggle <strong>Addresses and Address Groups<\/strong> or <strong>FortiGuard Reputable Websites<\/strong> to enable built-in system exemptions for known applications that use certificate pinning.<\/li>\n<li>Click <strong>OK<\/strong> to save the security profile.<\/li>\n<\/ol>\n<h3>Step 3: Apply the Inspection Profile to the Firewall Policy<\/h3>\n<p>The inspection profile takes effect only when applied to an active firewall policy handling outbound internet traffic.<\/p>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; Firewall Policy<\/strong>.<\/li>\n<li>Locate policy ID <code>10<\/code> (or create a new policy) permitting outbound LAN-to-WAN traffic.<\/li>\n<li>Set <strong>Incoming Interface<\/strong> to <code>port2<\/code> and <strong>Outgoing Interface<\/strong> to <code>port1<\/code>.<\/li>\n<li>Set <strong>Source<\/strong> to <code>CORP_LAN_192.0.2.0_24<\/code> and <strong>Destination<\/strong> to <code>all<\/code>.<\/li>\n<li>Set <strong>Service<\/strong> to <code>HTTPS<\/code>, <code>HTTP<\/code>, and <code>DNS<\/code>.<\/li>\n<li>Scroll down to <strong>Security Profiles<\/strong> and toggle the switch to enable profiles.<\/li>\n<li>Enable <strong>SSL Inspection<\/strong> and select <code>Deep_Inspection_Enterprise<\/code> from the dropdown.<\/li>\n<li>Enable supplementary security profiles, such as <strong>Antivirus<\/strong>, <strong>Web Filter<\/strong>, and <strong>Application Control<\/strong>.<\/li>\n<li>Ensure <strong>NAT<\/strong> is enabled, then click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h2>CLI Configuration<\/h2>\n<p>For network engineers deploying via automation, scripts, or SSH, the equivalent FortiOS CLI syntax is provided below. This syntax applies directly to standard FortiOS 7.x code streams.<\/p>\n<h3>Step 1: Configure the SSL\/SSH Profile<\/h3>\n<pre>\nconfig firewall ssl-ssh-profile\n    edit \"Deep_Inspection_Enterprise\"\n        set comment \"Corporate SSL Deep Inspection with Exemption List\"\n        set server-cert-mode re-sign\n        set can-sign-ca \"Enterprise_SubCA\"\n        set untrusted-cert block\n        config https\n            set ports 443\n            set status deep-inspection\n            set client-certificate bypass\n        end\n        config ftps\n            set status disable\n        end\n        config imaps\n            set status disable\n        end\n        config pop3s\n            set status disable\n        end\n        config smtps\n            set status disable\n        end\n        config ssh\n            set status disable\n        end\n        config ssl-exemption\n            edit 1\n                set type fortiguard-service\n                set fortiguard-service 11 15\n            next\n        end\n    next\nend\n<\/pre>\n<p><em>Note: FortiGuard service IDs 11 and 15 map to &#8220;Finance and Banking&#8221; and &#8220;Health and Wellness&#8221; in standard FortiOS database revisions. Always confirm mapping on your specific device.<\/em><\/p>\n<h3>Step 2: Apply Profile to Firewall Policy<\/h3>\n<pre>\nconfig firewall policy\n    edit 10\n        set name \"Outbound_Corporate_Access\"\n        set srcintf \"port2\"\n        set dstintf \"port1\"\n        set action accept\n        set srcaddr \"CORP_LAN_192.0.2.0_24\"\n        set dstaddr \"all\"\n        set schedule \"always\"\n        set service \"HTTPS\" \"HTTP\"\n        set utm-status enable\n        set ssl-ssh-profile \"Deep_Inspection_Enterprise\"\n        set av-profile \"default\"\n        set webfilter-profile \"default\"\n        set application-list \"default\"\n        set nat enable\n    next\nend\n<\/pre>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding the internal session creation and packet handling sequence helps engineers isolate performance or connectivity issues faster.<\/p>\n<ol>\n<li><strong>Session Initiation:<\/strong> The corporate endpoint (192.0.2.50) initiates a TCP 3-way handshake to destination host 203.0.113.50 on port 443.<\/li>\n<li><strong>Policy Match &amp; Route Lookup:<\/strong> The FortiGate inspects the SYN packet, identifies an outgoing route via <code>port1<\/code>, and matches firewall policy ID <code>10<\/code>.<\/li>\n<li><strong>Client Hello Interception:<\/strong> The client sends a TLS Client Hello packet. The FortiGate proxy daemon (<code>sslprx<\/code>) intercepts the packet.<\/li>\n<li><strong>Server SNI &amp; Exemption Check:<\/strong> The FortiGate evaluates the Server Name Indication (SNI) extension against configured exemptions (e.g., banking domains or pinned application lists).\n<ul>\n<li><em>If exempted:<\/em> The FortiGate steps out of the middle, allowing a direct, un-intercepted TLS tunnel to form. Decryption does not occur.<\/li>\n<li><em>If NOT exempted:<\/em> The process continues to step 5.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Upstream Handshake:<\/strong> The FortiGate opens an independent TLS connection to the actual web server (203.0.113.50) to validate its certificate chain, cipher suites, and trust status.<\/li>\n<li><strong>Dynamic Certificate Generation:<\/strong> The FortiGate takes the server&#8217;s real identity (e.g., <code>example.com<\/code>) and generates a temporary certificate on the fly, signing it with the internal <code>Enterprise_SubCA<\/code> private key.<\/li>\n<li><strong>Downstream Handshake:<\/strong> The FortiGate completes the TLS handshake back to the internal client using this freshly minted certificate.<\/li>\n<li><strong>Decrypted Inspection:<\/strong> Data sent between client and server is converted to cleartext within the FortiGate engine memory, allowing UTM engines (AV, IPS, Web Filter) to evaluate payload content.<\/li>\n<li><strong>Re-encryption and Egress:<\/strong> The FortiGate re-encrypts clean traffic and sends it out over interface <code>port1<\/code> to the destination.<\/li>\n<\/ol>\n<h2>Verification<\/h2>\n<p>Verify that SSL deep inspection operates as expected using both client-side and FortiGate system checks.<\/p>\n<h3>1. Client Browser Verification<\/h3>\n<p>Open a web browser on endpoint <code>192.0.2.50<\/code> and navigate to a non-exempt site (e.g., <code>https:\/\/example.com<\/code>). Click the padlock icon in the browser address bar and inspect the certificate details:<\/p>\n<ul>\n<li><strong>Issued To:<\/strong> <code>example.com<\/code><\/li>\n<li><strong>Issued By:<\/strong> <code>Enterprise_SubCA<\/code> (Your internal Intermediate CA name).<\/li>\n<\/ul>\n<p>If the certificate hierarchy reflects your local CA and no browser untrusted warning appears, decryption and endpoint trust are functioning perfectly.<\/p>\n<p>Next, navigate to a banking site (e.g., an exempted domain). Inspect the certificate again:<\/p>\n<ul>\n<li><strong>Issued By:<\/strong> DigiCert, Let&#8217;s Encrypt, or another public CA.<\/li>\n<\/ul>\n<p>This confirms that the bypass engine correctly matches and bypasses exempted traffic categories.<\/p>\n<h3>2. Active Session Inspection via CLI<\/h3>\n<p>Check the active firewall session table on the FortiGate to verify that the profile is attached to real-time traffic sessions:<\/p>\n<pre>\ndiagnose sys session filter src 192.0.2.50\ndiagnose sys session filter dport 443\ndiagnose sys session list\n<\/pre>\n<p>Look for session output lines indicating proxy handling and SSL profile attachment, such as:<\/p>\n<pre>\n...\nproto=6 proto_state=01 state=log may_dirty ndr auth offer_sdata npu_bypass\nstatistic(bytes\/pkts\/mask): total=4215\/28\/1 orig=2012\/14\/1 redir=2203\/14\/1\n...\nhelper=https security_profile_list: ssl-ssh:Deep_Inspection_Enterprise\n...\n<\/pre>\n<h2>Troubleshooting<\/h2>\n<p>Deploying SSL deep inspection frequently uncovers application incompatibilities or trust issues. Follow this structured approach to diagnose issues.<\/p>\n<div class=\"caution\">\n  <strong>CAUTION:<\/strong> Running real-time debug daemons increases CPU load and prints sensitive traffic parameters to your SSH terminal. Always apply strict filters and run <code>diagnose debug reset<\/code> immediately after testing.\n<\/div>\n<h3>Symptom 1: Client Browser Shows &#8220;NET::ERR_CERT_AUTHORITY_INVALID&#8221;<\/h3>\n<ul>\n<li><strong>Likely Cause:<\/strong> The endpoint does not trust the signing CA configured on the FortiGate.<\/li>\n<li><strong>Diagnostic Step:<\/strong> On the Windows endpoint, run <code>certutil -store Root<\/code> or check <code>certmgr.msc<\/code> to verify whether <code>Enterprise_SubCA<\/code> or its parent Root CA exists in the **Trusted Root Certification Authorities** container.<\/li>\n<li><strong>Resolution:<\/strong> Re-deploy the CA certificate to endpoints via Active Directory GPO, Intune, or MDM framework.<\/li>\n<\/ul>\n<h3>Symptom 2: Proprietary Application Fails to Connect (Certificate Pinning)<\/h3>\n<ul>\n<li><strong>Likely Cause:<\/strong> Applications like Dropbox, Spotify, or cloud syncing clients check for hardcoded public certificates and reject proxy certificates.<\/li>\n<li><strong>Diagnostic Step:<\/strong> Enable real-time SSL proxy debugging on the FortiGate while reproducing the connection attempt.<\/li>\n<\/ul>\n<pre>\ndiagnose debug reset\ndiagnose debug application sslprx -1\ndiagnose debug enable\n<\/pre>\n<p>Observe the debug stream for failed handshake records or alert messages such as <code>fatal alert: unknown CA<\/code> or proxy connection resets.<\/p>\n<p>After observing the issue, disable the debug trace safely:<\/p>\n<pre>\ndiagnose debug disable\ndiagnose debug reset\n<\/pre>\n<ul>\n<li><strong>Resolution:<\/strong> Add the destination domain or IP subnet to the SSL inspection profile bypass list under <strong>Addresses and Address Groups<\/strong> or <strong>Custom Categories<\/strong>.<\/li>\n<\/ul>\n<h3>Symptom 3: High CPU Load on FortiGate After Enabling Profile<\/h3>\n<ul>\n<li><strong>Likely Cause:<\/strong> High volume of concurrent SSL sessions pushing software processing limits.<\/li>\n<li><strong>Diagnostic Step:<\/strong> Check process usage for the proxy daemon and overall CPU breakdown:<\/li>\n<\/ul>\n<pre>\ndiagnose sys top 2 20\n<\/pre>\n<p>Observe if processes such as <code>sslprx<\/code> or <code>wad<\/code> consume excessive CPU percentage.<\/p>\n<ul>\n<li><strong>Resolution:<\/strong> Ensure that high-bandwidth, non-threat traffic (such as internal backup endpoints, video streaming, or trusted software updates) is separated into distinct firewall policies where SSL deep inspection is turned off.<\/li>\n<\/ul>\n<h2>Common Mistakes<\/h2>\n<ul>\n<li><strong>Inspecting All Traffic Universally:<\/strong> Enabling deep inspection on a blanket policy without excluding financial, health, and pinned-app domains will inevitably break core user applications and spark end-user complaints.<\/li>\n<li><strong>Forgetting Certificate Revocation Lists (CRL):<\/strong> If the internal CA cannot be validated or lacks an accessible CRL distribution point, modern browsers may reject re-signed certificates.<\/li>\n<li><strong>Using the Default Fortinet Factory Certificate:<\/strong> Relying on the default internal <code>Fortinet_CA<\/code> certificate for deep inspection forces every end-user browser to display untrusted warnings until manually imported across all endpoints. Always use an internal PKI subordinate certificate.<\/li>\n<li><strong>Ignoring TLS 1.3 Drafts and ECH:<\/strong> Encrypted Client Hello (ECH) masks the SNI header. If ECH is active on client browsers, domain-based exemptions will fail unless disabled via browser administrative templates or DNS policy.<\/li>\n<\/ul>\n<h2>Production Considerations<\/h2>\n<p>To maintain performance, availability, and regulatory compliance, review these operational guidelines before rolling out deep inspection at scale:<\/p>\n<ul>\n<li><strong>Phased Rollout:<\/strong> Do not enable deep inspection globally in a single change window. Deploy the profile to a pilot User Acceptance Testing (UAT) subnet first. Expand to additional organizational units (OUs) over 3\u20134 weeks.<\/li>\n<li><strong>Sizing and Offloading:<\/strong> Review hardware platform specifications. FortiGate desktop and mid-range enterprise models include CP9 or CP10 co-processors that accelerate TLS decryption. Ensure your current model has sufficient throughput capacity for proxy-based UTM loads.<\/li>\n<li><strong>Legal Exemption Policy:<\/strong> Work directly with corporate legal and HR teams to document exempted site categories clearly. Post a clear Acceptable Use Policy (AUP) notifying employees that corporate internet access is subject to decrypted security monitoring.<\/li>\n<li><strong>Bypass List Maintenance:<\/strong> Maintain a operational runbook for adding custom domain exceptions quickly when cloud providers update application endpoints or implement strict certificate pinning.<\/li>\n<\/ul>\n<h2>Related FortiGate Guides<\/h2>\n<ul>\n<li><a href=\"\/tutorials\/fortinet\/apply-fortigate-security-profiles-to-firewall-policies\/\">Apply FortiGate security profiles to firewall policies<\/a><\/li>\n<li><a href=\"\/tutorials\/fortinet\/fortigate-session-troubleshooting-with-flow-debug-sessions-and-logs\/\">FortiGate session troubleshooting<\/a><\/li>\n<li><a href=\"\/tutorials\/fortinet\/fortigate-packet-sniffer-and-debug-flow-for-real-troubleshooting\/\">FortiGate packet sniffer and debug flow<\/a><\/li>\n<li><a href=\"\/tutorials\/fortinet\/fortigate-syslog-configuration-and-verification-for-siem-integration\/\">FortiGate Syslog and SIEM integration<\/a><\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>Deploying <strong>FortiGate SSL deep inspection<\/strong> removes critical visibility blind spots, allowing enterprise security teams to detect advanced threats hiding inside encrypted HTTPS streams. By leveraging an enterprise PKI subordinate certificate, applying selective category exemptions, and monitoring proxy daemons, administrators can implement rigorous content filtering without disrupting key business operations or compromising user privacy.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Configure FortiGate SSL deep inspection and troubleshoot certificates, policy scope, browser trust and inspection failures.<\/p>","protected":false},"author":2,"featured_media":1412,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[4],"tags":[137,29,41,1165,44,43,1166],"class_list":["post-1413","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fortinet","tag-advanced","tag-firewall-tutorial","tag-fortigate","tag-fortigate-ssl-deep-inspection","tag-fortinet","tag-fortios","tag-ssl-inspection"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>FortiGate SSL Deep Inspection: Configuration and Troubleshooting<\/title>\n<meta name=\"description\" content=\"Configure FortiGate SSL deep inspection and troubleshoot certificates, policy matching, browser errors and inspection failures.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FortiGate SSL Deep Inspection: Design, Configuration and Troubleshooting\" \/>\n<meta property=\"og:description\" content=\"Configure FortiGate SSL deep inspection and troubleshoot certificates, policy matching, browser errors and inspection failures.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-10T15:47:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-30T09:27:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting-featured.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"FortiGate SSL Deep Inspection: Design, Configuration and Troubleshooting\",\"datePublished\":\"2026-09-10T15:47:49+00:00\",\"dateModified\":\"2026-09-30T09:27:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/\"},\"wordCount\":1983,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting-featured.jpg\",\"keywords\":[\"Advanced\",\"Firewall Tutorial\",\"FortiGate\",\"FortiGate SSL deep inspection\",\"Fortinet\",\"FortiOS\",\"SSL Inspection\"],\"articleSection\":[\"FortiGate\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/\",\"name\":\"FortiGate SSL Deep Inspection: Configuration and Troubleshooting\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting-featured.jpg\",\"datePublished\":\"2026-09-10T15:47:49+00:00\",\"dateModified\":\"2026-09-30T09:27:40+00:00\",\"description\":\"Configure FortiGate SSL deep inspection and troubleshoot certificates, policy matching, browser errors and inspection failures.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting-featured.jpg\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting-featured.jpg\",\"width\":1200,\"height\":630,\"caption\":\"FortiGate SSL Deep Inspection: Design, Configuration and Troubleshooting\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FortiGate SSL Deep Inspection: Design, Configuration and Troubleshooting\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"FortiGate SSL Deep Inspection: Configuration and Troubleshooting","description":"Configure FortiGate SSL deep inspection and troubleshoot certificates, policy matching, browser errors and inspection failures.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/","og_locale":"en_US","og_type":"article","og_title":"FortiGate SSL Deep Inspection: Design, Configuration and Troubleshooting","og_description":"Configure FortiGate SSL deep inspection and troubleshoot certificates, policy matching, browser errors and inspection failures.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/","og_site_name":"NetworkFix","article_published_time":"2026-09-10T15:47:49+00:00","article_modified_time":"2026-09-30T09:27:40+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting-featured.jpg","type":"image\/jpeg"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"FortiGate SSL Deep Inspection: Design, Configuration and Troubleshooting","datePublished":"2026-09-10T15:47:49+00:00","dateModified":"2026-09-30T09:27:40+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/"},"wordCount":1983,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting-featured.jpg","keywords":["Advanced","Firewall Tutorial","FortiGate","FortiGate SSL deep inspection","Fortinet","FortiOS","SSL Inspection"],"articleSection":["FortiGate"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/","url":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/","name":"FortiGate SSL Deep Inspection: Configuration and Troubleshooting","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting-featured.jpg","datePublished":"2026-09-10T15:47:49+00:00","dateModified":"2026-09-30T09:27:40+00:00","description":"Configure FortiGate SSL deep inspection and troubleshoot certificates, policy matching, browser errors and inspection failures.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting-featured.jpg","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting-featured.jpg","width":1200,"height":630,"caption":"FortiGate SSL Deep Inspection: Design, Configuration and Troubleshooting"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-ssl-deep-inspection-design-configuration-and-troubleshooting\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"FortiGate SSL Deep Inspection: Design, Configuration and Troubleshooting"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1413","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=1413"}],"version-history":[{"count":2,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1413\/revisions"}],"predecessor-version":[{"id":1636,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1413\/revisions\/1636"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/1412"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=1413"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=1413"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=1413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}