In today's video, we'll show you the definitive step-by-step process to resolve certificate errors that appear when using security profiles that require SSL inspection or when you want to block HTTPS pages using WebFilter! 🛡️
When we activate features like Certificate Inspection or Deep Inspection to block websites (such as Instagram), browsers display privacy error alerts and invalid certificates. To fix this and ensure the FortiGate lock screen displays correctly, you need the machines on your network to trust your firewall's Certificate Authority (CA) (it's also possible to install a sub-CA on the FortiGate, but that's a topic for another video!).
If you work with infrastructure and need to keep your network secure without headaches for users, this content is a must!
#Fortinet #FortiGate #InformationSecurity #Firewall #Networks #GPO #ActiveDirectory #SecInfra #ITInfrastructure
🚀 Master Networks with EasyLab: Practice in real PNETLAB environments without needing expensive physical hardware.
https://www.easylabtraining.com/?src=...
📚 Certifications and Training: Learn Fortinet and Networking from those who understand the subject.
https://www.secinfra.com.br/links/?sr...
👥 SecInfra Community: Join our group and discuss hardware and security with us:
https://www.secinfra.com.br/links/gru...
🔔 By purchasing through the links below, you help the channel without paying ANYTHING extra!
Amazon: https://amzn.to/3TEzNJ6
Mercado Livre: https://mercadolivre.com/sec/2dLzBKE
🔔 Don't forget to like the video, share it with your friends and colleagues, and subscribe to the channel! 🔔
⏱️ CHAPTERS:
00:00 Certificate error in Web Filter blocking: why it happens
01:00 Why Certificate Inspection also needs a certificate CA
02:07 How FortiGate intercepts HTTPS traffic to display the lock screen
02:29 HSTS: why Instagram doesn't allow access with an invalid certificate
02:38 Manual installation of the FortiGate certificate on the machine
03:20 Why the manual method is unfeasible in environments with many machines
03:42 Distributing the certificate via GPO on the domain server (Active Directory)
04:41 Creating the GPO and importing it into Trusted Root Certification Authority
05:47 Applying the policy with gpupdate /force and testing the blocking
06:49 The certificate is used for Certificate Inspection and Deep Inspection