Hi everyone! New to the community and really excited to be here. I've been diving into FortiSASE at my company as we pilot it for our remote workforce.
We've started rolling it out, and I'm getting some consistent, odd reports from a few teammates. When they try to use specific mobile banking apps (like Chase and a couple of regional banks) on their phones with FortiSASE active, the apps fail to connect, throwing certificate errors or "cannot establish a secure connection" messages. It seems like the apps use certificate pinning and don't like the inspection.
Has anyone else run into this with modern banking or other high-security apps? I'm trying to understand:
* Is this a common known issue with SASE/ZTNA solutions?
* Are there recommended bypass policies for these specific app categories?
* Could it be related to a specific FortiSASE component or a general TLS inspection caveat?
I'd love any insights or walkthroughs on how you've configured policies to handle these exceptions without compromising security for other traffic. My current workaround is to have users toggle FortiSASE off for banking, which isn't ideal.
Thanks in advance for the help