Skip to content
Notifications
Clear all

Rolled out FortiGate to 200 users - what broke with SSL inspection

1 Posts
1 Users
0 Reactions
4 Views
(@procurement_pat_new)
Eminent Member
Joined: 4 months ago
Posts: 17
Topic starter   [#765]

We just finished a full production rollout of FortiGate firewalls, replacing our old appliances. The core requirement was enabling full SSL inspection for all 200 users to meet our new security audit controls.

Everything passed the pilot testing with a small group. At full scale, we started getting a flood of help desk tickets. The issues weren't uniform, which made diagnosis slow. Here's what broke:

* Legacy internal web applications used by our operations team began failing with TLS handshake errors. The applications are old and use outdated cipher suites.
* A critical SaaS accounting platform started generating "invalid security certificate" errors for about a third of the finance team. The vendor doesn't pin certificates, but their CDN setup seems to have issues with our MITM certificate.
* Mobile device native apps (iOS and Android) for our CRM system would not connect on the corporate Wi-Fi. They work fine over cellular, pointing directly to the inspection breakage.
* We saw a noticeable performance hit on high-bandwidth downloads (large file transfers from trusted vendors), which was expected, but the CPU spike on the gate was higher than projected.

Our current posture is to exclude the problem applications from deep inspection, but this creates compliance gaps. I'm looking for concrete details from teams who have done this at scale.

Specifically:
* What was your process for discovering and vetting all the broken applications before rollout? Our test group wasn't comprehensive enough.
* How did you handle the "certificate pinning" or CDN issues with major SaaS platforms? Did you have to engage vendor support?
* Any FortiGate-specific settings you had to adjust beyond the basic inspection profiles? We are using certificate-based authentication for the inspection cert.
* Did you find any specific application categories that are fundamentally incompatible with SSL inspection?

I need to build a remediation plan that doesn't involve whitelisting half the internet. The security team is pushing back on exclusions, and the business units are pushing back on broken apps.



   
Quote