Around the 12:50 mark, I get a bit confused. You are editing a web filter rule on an inbound traffic policy to test (in normal circumstances) what would be incoming traffic. Did I miss something or just not had enough coffee yet?
@tothepointfortinet38232 жыл бұрын
Yeah good point, I think it was valid to prove the test but a better use case might have been a virus upload for example
@OOSULLIVAN Жыл бұрын
In lieu of creating 2 https sessions (client to fw and fw to internal server), can one upload the internal server certificate on the firewall? Would this also allow the FW to decrypt traffic to the internal server? Or is it necessary for the client to connect to the FW first.
@tothepointfortinet3823 Жыл бұрын
Yes you can upload the server cert to the firewall and so that the firewall can decrypt the traffic -> this is the approach taken in this video. I do not know of a way to have this type of decryption visibility inbound without the client connecting to the firewall first when we using a port forwarding type scenario.