FortiGate SSL Inspection

Encrypted traffic inspection planning for business networks

FortiGate SSL Inspection in Dubai, UAE

Encryption protects data in transit, but it can also reduce what a firewall can examine inside a connection. FortiGate SSL Inspection gives security teams a policy-driven way to decide when certificate-level visibility is enough and when selected traffic should be decrypted for deeper security inspection. A successful deployment depends on firewall sizing, FortiOS version, certificate trust, application behaviour, privacy policy and the security profiles applied after decryption.

Inspection choiceCertificate or deep inspection
Key dependencyTrusted CA on managed endpoints
Sizing factorSSL inspection throughput by model
Operational needTesting and exemption governance
UAE next stepConfirm model, license and scope

Direct answer: what FortiGate SSL Inspection does

FortiGate SSL Inspection controls how encrypted SSL/TLS and, where configured, SSH traffic is examined by firewall security policies. Certificate inspection looks at the connection and certificate information without opening the encrypted payload. Deep inspection goes further: the FortiGate acts as an intermediary, decrypts the session, allows enabled security profiles to inspect the content, and then re-encrypts traffic. Organisations with managed endpoints and a clear inspection policy are the strongest candidates. Before proceeding, confirm the FortiGate model and performance headroom, FortiOS version, certificate distribution method, security-service licensing, application compatibility, legal or privacy exclusions, and the testing plan for users and business-critical applications.

What it does inside a FortiGate policy

An SSL/SSH inspection profile is associated with firewall policies that need encrypted-traffic handling. The profile determines the inspection method, certificate behaviour, protocol and port handling, treatment of invalid server certificates, and any defined exemptions. That inspection result then supports other controls applied to the same traffic path.

The practical value is not simply that traffic is decrypted. The value comes from giving security profiles enough visibility to make the decision you expect. If web filtering, application control, intrusion prevention or malware inspection must examine information that is hidden inside TLS, the inspection design has to provide that visibility without creating avoidable user disruption.

Who should consider it

FortiGate SSL Inspection is most suitable for organisations that manage their own endpoints, use central certificate distribution, depend on FortiGate security profiles for outbound internet controls, or need greater visibility into encrypted application traffic. It is also relevant to organisations reviewing why security policies appear less effective when users move from unencrypted to HTTPS-based services.

It is less straightforward for unmanaged BYOD networks, public guest access, highly diverse device estates, applications that use certificate pinning, and environments with strict privacy or regulatory restrictions. Those cases do not automatically rule out inspection, but they require careful scope decisions and often a more selective policy design.

Business problems the inspection design should solve

A useful design begins with a problem statement rather than enabling deep inspection everywhere. The following challenges are common reasons for reviewing FortiGate encrypted-traffic handling.

Security controls cannot see enough

Encrypted payloads may hide files, commands or application actions from controls that need content visibility. Deep inspection may expose that content to the security profiles configured on the policy.

Web policy needs greater precision

Certificate inspection can identify connection-level information, but it does not open the encrypted payload. A deeper policy may be required where content-level inspection is necessary.

Users see certificate warnings

Deep inspection depends on endpoint trust. If the inspection CA is not trusted correctly, browsers and applications can report certificate errors or refuse connections.

Applications break after rollout

Pinned certificates, mutual TLS, unusual TLS stacks and unmanaged devices can behave differently under interception. Testing and controlled exemptions are part of a production-ready design.

Core FortiGate SSL Inspection capabilities

FortiGate provides several mechanisms for dealing with encrypted traffic. Which one to use depends on the business outcome, endpoint ownership, protocol mix and current FortiOS capability on the selected hardware.

Certificate inspection

Examines SSL/TLS connection information and server certificates without decrypting the application payload. It is easier to deploy and may be appropriate when policy goals do not require content inspection.

Deep inspection

Decrypts traffic, exposes the content to configured security controls, and re-encrypts it. This provides deeper visibility but introduces certificate, performance, application and privacy considerations.

Custom inspection profiles

Administrators can create profiles for different user groups or network segments, selecting certificates, protocol handling, invalid-certificate behaviour and exemptions according to policy requirements.

Exemption handling and logging

Exclusions can be used where inspection is unsuitable, and FortiOS includes options to log SSL exemptions. Exemption design should be controlled, documented and reviewed rather than used as a quick fix for every application problem.

Fit matrix: when each inspection approach makes sense

RequirementSuitable whenConfirm before proceeding
Basic HTTPS destination visibilityCertificate-level information is enough for the policy objective.Whether payload inspection is actually required by any enabled security profile.
Content-aware security controlsManaged endpoints can trust an inspection CA and the organisation needs visibility inside TLS.SSL inspection throughput, application compatibility, exclusions and security-service licensing.
BYOD or guest networksCertificate inspection or a carefully limited design may be more practical.Whether the organisation can legitimately and technically install trust on those devices.
Business applications using certificate pinning or mutual TLSOften needs an exemption, app-specific handling or vendor-supported design.Application owner guidance and controlled testing.
High-bandwidth internet edgeDeep inspection can be considered when the selected FortiGate has sufficient measured headroom for the real traffic mix.Model-specific SSL inspection throughput, session profile, TLS versions, other enabled security services and growth margin.

Technical and service information

This is a FortiGate security capability and implementation topic rather than one fixed appliance model. Values such as SSL inspection throughput, ports, memory and maximum sessions vary by FortiGate model, so they should not be blended into a single specification claim.

TopicFortiGate SSL/SSH inspection, including certificate inspection and deep inspection
Main purposeControl how encrypted traffic is inspected so firewall security policies can receive the visibility they require.
FortiOS configuration areaSSL/SSH Inspection profiles associated with firewall policies; exact menu labels and options can vary by FortiOS release.
Certificate inspectionInspects information up to the SSL/TLS layer without opening the encrypted content payload.
Deep inspectionFortiGate intermediates the TLS connection, decrypts, inspects through configured security controls, and re-encrypts traffic.
CA certificateRequired for a trusted deep-inspection experience on managed endpoints. Enterprise PKI use is commonly preferable in centrally managed environments.
Protocols and portsConfigurable in the inspection profile; exact protocol support and behaviour are FortiOS-version dependent.
HTTP/2, HTTP/3, QUIC and newer TLS behaviourSupport is version, inspection mode and configuration dependent. Confirm against the FortiOS release installed on the target model.
Encrypted Client Hello and newer cryptographyHandling continues to evolve across FortiOS releases. Current behaviour should be tested in the exact software version before broad rollout.
Security service dependenciesThe inspection profile provides visibility; web, malware, application, intrusion and other controls may depend on selected FortiGuard services or license bundles.
PerformanceModel dependent. Fortinet publishes SSL Inspection Throughput for individual models, typically measured using an average of HTTPS sessions with specified test conditions.
ExemptionsCan be used for destinations or categories that should not be decrypted. Exemption design should follow business, privacy and application requirements.
Deployment supportRequirement review, model sizing, certificate planning, inspection-profile design, staged rollout, troubleshooting and documentation can be included by quotation.
AvailabilityContact FourTeck to confirm current UAE appliance, subscription, renewal and configuration-service options.
Dependency notice

Deep inspection should not be treated as a checkbox that can be enabled safely on every policy without preparation. The firewall must generate or use inspection certificates that endpoints trust. Applications using certificate pinning, mutual TLS, device certificates or unusual TLS implementations may reject interception. Privacy-sensitive traffic may need documented exclusions. Performance must be checked against the exact FortiGate model and the set of security profiles that will run on decrypted traffic.

Licensing is also separate from the inspection method itself. The value of decrypted visibility often comes from security controls such as web filtering, antivirus, application control or intrusion prevention, and the availability of those services depends on the selected FortiGate subscription and FortiOS feature set. Confirm the bill of materials and current license status before designing the production policy.

A practical deployment journey

01

Define the inspection objective

List which security controls need more visibility and which user groups, VLANs or outbound policies are in scope. This prevents an unnecessarily broad rollout.

02

Check model and software readiness

Review the FortiGate model, FortiOS release, SSL inspection throughput, session load, inspection mode and enabled security services. Plan upgrades separately where required.

03

Choose the CA strategy

Decide whether to use a FortiGate-generated CA or an enterprise PKI approach. Managed organisations should plan central trust distribution and certificate lifecycle ownership.

04

Build a pilot policy

Apply the profile to a controlled test group. Validate browsing, Microsoft 365 or other cloud services, line-of-business apps, mobile apps, updates, VPN-related flows and any known pinned-certificate applications.

05

Document exemptions

Every exemption should have a reason, owner and review point. Avoid turning the exception list into an uncontrolled bypass of the security objective.

06

Expand and monitor

Increase scope in stages, monitor user impact and firewall resource behaviour, and keep rollback conditions defined. Preserve configuration backups and change documentation.

Certificate trust is the foundation of deep inspection

When FortiGate performs deep inspection for outbound HTTPS, it must present a certificate to the client on behalf of the destination website. The client accepts that certificate only when it trusts the CA that signed it. This is why certificate planning is not a minor technical detail; it is the control that determines whether the user sees a normal connection or a certificate warning.

For a small controlled environment, administrators may distribute the FortiGate inspection certificate to managed endpoints. In a larger Active Directory or device-management environment, an enterprise PKI approach may provide better ownership, distribution and lifecycle control. The correct choice depends on the customer’s endpoint-management platform, security governance and certificate-management maturity. FourTeck can help map the FortiGate configuration to the customer’s existing endpoint administration method, but certificate authority ownership and organisational trust policy should remain clearly defined by the customer.

Unmanaged devices deserve separate treatment. Guest phones, contractors’ laptops, personal tablets and specialised appliances may not accept an organisation’s CA or may not be under appropriate administrative control. For those segments, certificate inspection or a separate policy may be more practical than forcing deep inspection. A segmented design is often easier to support than a single inspection profile applied to every user and every device.

Performance sizing must use SSL inspection data, not firewall throughput alone

A FortiGate can process ordinary firewall traffic at a very different rate from traffic that is decrypted, passed through security engines and re-encrypted. For this reason, the headline firewall throughput number is not enough for a project that expects substantial deep inspection. Fortinet publishes model-specific SSL inspection throughput measurements, and those figures are the more relevant starting point when encrypted traffic will be a large portion of internet usage.

Sizing still requires interpretation. Real networks contain a mixture of TLS versions, cipher suites, session sizes, short-lived connections, long-lived SaaS sessions, uploads, downloads and different security profiles. User count alone is also a weak metric. Fifty users transferring large cloud backups can create a different inspection load from several hundred users performing light web activity. The model review should therefore consider measured internet bandwidth, expected growth, peak utilisation, session behaviour, the security controls enabled on inspected traffic and high-availability requirements.

When a customer already owns the firewall, FourTeck can help review whether the current appliance has reasonable headroom before inspection is expanded. When a new firewall is being selected, the bill of materials should be built around inspected traffic and business continuity needs rather than purchasing the smallest model that meets basic routing throughput.

Application compatibility and the discipline of exemptions

Modern business applications do not all behave like a standard browser. Some clients use certificate pinning so they will accept only a specific certificate or public key. Some systems use mutual TLS, where both sides of the connection authenticate with certificates. Other applications use embedded TLS libraries, specialised devices or cloud-service update channels that react badly to interception. These are normal design realities, not reasons to abandon inspection altogether.

The right response is a controlled test and exception process. Identify critical applications before rollout, test them with the planned inspection profile, record failures, establish whether the application vendor supports interception, and create the narrowest practical exemption when deep inspection is not suitable. Exemptions may be based on destinations, categories or other supported criteria depending on FortiOS version and policy structure. FortiGate can log SSL exemptions, which helps security teams review how much traffic is bypassing decryption.

Privacy-sensitive sites should also be governed intentionally. Organisations may choose not to decrypt categories involving personal health, financial activity or other sensitive content, depending on internal policy and applicable legal requirements. FourTeck can help implement an approved exemption design, but the customer should decide what may be inspected and should involve its legal, compliance or HR stakeholders where appropriate.

Where FortiGate SSL Inspection fits well

Managed office endpoints

Windows, macOS and other centrally administered endpoints can receive the inspection CA through enterprise management, making deep inspection easier to govern and support.

Branch internet breakout

Branches using local FortiGate internet access can apply policy-based inspection where the appliance is sized for the local bandwidth and a consistent certificate policy is available.

Security profile enforcement

Organisations relying on FortiGate web, application, intrusion or malware controls may need deeper TLS visibility for certain policy outcomes.

Controlled server protection

FortiGate also has designs for inspecting traffic to protected SSL servers. The certificate, server role, policy direction and application architecture should be evaluated separately from outbound user inspection.

Integration and operational considerations

SSL inspection touches more than the firewall team. Endpoint management is needed to distribute trusted certificates. Application owners are needed to test business software. Security teams decide which threat controls should act on decrypted traffic. Compliance or legal stakeholders may define categories that must remain private. Network teams must plan capacity and high availability. Help-desk staff need a troubleshooting path for certificate warnings and blocked applications. Treating the project as a cross-functional change usually produces a more supportable result.

FortiManager may be relevant in multi-FortiGate environments where central configuration and certificate deployment are required, while FortiAnalyzer may support logging and investigation depending on the broader architecture. These platforms are not automatically required for SSL inspection, and their licensing and design should be reviewed separately. Existing enterprise PKI services, Active Directory Group Policy, MDM/UEM platforms and software-distribution tools may also be involved in certificate rollout.

Newer protocols deserve version-specific validation. Current FortiOS releases include evolving support for areas such as HTTP/2, HTTP/3, QUIC, encrypted client hello and newer TLS cryptography. Behaviour can differ by flow-based or proxy-based inspection and by FortiOS version. An implementation plan should therefore be based on the software actually running on the customer’s FortiGate rather than assumptions taken from an older configuration guide.

Questions to resolve before requesting a quote

Which FortiGate model and FortiOS release are in use?

This determines the available options, model-specific inspection performance and whether a software change should be planned first.

How much traffic is expected to be deeply inspected?

Share internet bandwidth, peak utilisation, user count, major SaaS applications and any growth target. Sizing should reflect encrypted traffic, not only total firewall throughput.

Can endpoints receive a trusted CA centrally?

Identify Active Directory, MDM/UEM or other endpoint management methods and separate managed corporate devices from BYOD and guest devices.

Which applications are business-critical?

ERP, banking, payment, voice, collaboration, cloud storage, software update and custom applications should be listed for pilot testing and exemption planning.

What must not be decrypted?

Document privacy, legal, compliance and application-driven exclusions before the technical configuration is finalised.

Which licensed security profiles should inspect the content?

Clarify web filtering, application control, IPS, antivirus or other controls so the license bundle and expected inspection path can be reviewed.

Procurement and implementation checklist

✓ Exact FortiGate model and hardware revision
✓ Current and target FortiOS release
✓ Internet bandwidth and peak utilisation
✓ Required SSL inspection coverage by user or VLAN
✓ Existing FortiGuard subscription and expiry
✓ Certificate authority and endpoint trust method
✓ BYOD, guest and unmanaged-device treatment
✓ Business-critical and pinned-certificate applications
✓ Privacy and compliance exemptions
✓ Pilot users and rollback plan
✓ High-availability or maintenance-window requirements
✓ Configuration backup and documentation scope
✓ On-site or remote implementation requirement
✓ Target deployment date and change approval process

How FourTeck can assist with planning and rollout

FourTeck can support FortiGate SSL Inspection as part of a new firewall deployment, an existing-firewall hardening exercise, a security-profile review or a troubleshooting project. Assistance can begin with requirement clarification: identifying the policies that need inspection, the user groups in scope, the current FortiGate model, FortiOS release, bandwidth, certificate environment and existing license bundle.

For new projects, FourTeck can help buyers compare FortiGate models using the inspection requirement rather than basic firewall throughput alone. The team can also help prepare a bill of materials that includes the appliance, relevant subscriptions, support coverage and implementation scope where needed. For existing FortiGate environments, the engagement can focus on certificate strategy, custom SSL/SSH inspection profiles, pilot policies, exemptions, application testing, troubleshooting and change documentation.

Customers can also review related firewall services, browse firewall product options, or request broader Fortinet firewall guidance. The most useful quotation request includes the exact firewall model, quantity when hardware is required, subscription status, internet bandwidth, number of users, inspection objective and whether installation or configuration assistance should be included.

FourTeck does not assume that one inspection method suits every customer. The objective is to help the buyer understand the trade-offs, confirm the technical dependencies and build an implementation path that can be tested before broad production use.

UAE availability and support guidance

FortiGate SSL Inspection is not a single standalone appliance that can be quoted accurately without understanding the underlying firewall and security services. For a UAE requirement, first confirm whether the project needs a new FortiGate, a license renewal, a FortiOS change, certificate deployment, inspection-profile configuration or a wider security review. Availability may depend on the exact FortiGate model, subscription bundle, quantity, vendor lead time and implementation scope.

FourTeck can assist businesses in Dubai, Abu Dhabi, Sharjah and Ajman through one coordinated UAE requirement review covering product selection, licensing, quotation, delivery planning and configuration scope. Installation dates, site work and change windows should be agreed only after the environment and required services are confirmed. Use the FourTeck firewall contact page to share the model, FortiOS release, license status and inspection objective.

GCC Availability

Organisations operating across the Gulf often need a consistent inspection policy while working with different internet links, local IT teams, endpoint-management practices and procurement processes. FourTeck can assist with requirement review, FortiGate model or license selection, quotation coordination, certificate-planning discussions, configuration scope, installation planning and renewal guidance for projects involving the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain and Oman. A regional design should not assume that every branch has the same appliance capacity or that the same exception list will work everywhere. The destination country, FortiGate model, quantity, subscription term, software version, deployment location and expected timeline should be shared before quotation or service planning.

Product availability, license eligibility, vendor lead times, delivery schedules and service-visit options can vary by country and requirement. FourTeck can coordinate regional inquiries and help standardise the information needed for a multi-site project, but stock, customs handling, fixed delivery dates and onsite coverage should be confirmed for each destination. For Kuwait-specific business inquiries, the FourTeck Kuwait platform may also be relevant.

Africa Availability

For African deployments, SSL inspection planning should include not only the FortiGate model but also endpoint certificate distribution, local internet capacity, branch topology, power and rack conditions, subscription region, remote administration and the availability of local technical resources. FourTeck can help organisations evaluate FortiGate appliances, subscriptions, accessories, configuration scope, support requirements and renewal planning for projects across selected African markets. Businesses with operations in East Africa can also use FourTeck regional resources for Kenya and Uganda, while wider regional inquiries can be coordinated through the Africa platform.

Availability and fulfilment can depend on destination country, exact model, quantity, license region, shipping arrangements, vendor lead time and local project conditions. Share the destination, required FortiGate model if known, internet bandwidth, expected user count, planned inspection scope, preferred deployment schedule and any installation or support expectations. FourTeck can then help identify the next procurement or technical step without assuming local inventory or a guaranteed delivery timeline. Explore FourTeck Africa for broader regional inquiries or FourTeck Kenya for Kenya-focused requirements.

Related options and supporting services

FortiGate model sizing

Review appliance capacity using expected SSL inspection load, sessions, security profiles and growth requirements.

View firewall products →

Firewall configuration

Combine SSL inspection with policy, routing, NAT, segmentation and security-profile configuration where the project needs wider changes.

Explore firewall services →

Fortinet firewall consultation

Useful when the requirement includes a new FortiGate, license selection, renewal or broader security architecture.

Review Fortinet guidance →

Deployment support

Plan staged implementation, certificate trust, testing, rollback and documentation for an existing or new firewall.

Discuss deployment scope →

Why businesses contact FourTeck for this requirement

SSL inspection projects often begin with a simple question—“Should we enable deep inspection?”—and quickly reveal dependencies involving model capacity, endpoint trust, license status, application compatibility and policy governance. Businesses contact FourTeck when they want those dependencies reviewed together rather than receiving only a firewall SKU or a generic configuration checklist.

The engagement can focus on requirement clarification, identifying which traffic actually needs content inspection, checking the current FortiGate and FortiOS version, reviewing FortiGuard subscriptions, selecting an inspection certificate strategy, planning exclusions, defining a pilot group and identifying the information needed for a realistic quotation. Where hardware replacement is necessary, FourTeck can also help compare suitable FortiGate models and prepare the related bill of materials.

This approach is useful for IT managers who need a practical next step, procurement teams that need clearer scope before seeking price approval, and system administrators who need assistance turning a broad security objective into a controlled change plan. Product availability, service scope, warranty handling and delivery coordination remain requirement dependent and should be confirmed during the quotation process.

What buyers usually need to understand before choosing deep inspection

Most buyers do not start with a FortiOS menu. They start with symptoms: web filtering misses activity inside encrypted sites, malware controls need better visibility, users receive certificate warnings after a test, or a security audit asks how the organisation handles encrypted outbound traffic. The useful answer is therefore not “turn on deep inspection everywhere.” The useful answer is to match the inspection method to the business requirement and the device population.

Does FortiGate inspect HTTPS without decrypting it?

Yes, certificate inspection provides connection and certificate-level visibility without opening the encrypted application payload. It can be a sensible option when the policy goal is destination or certificate awareness and the organisation does not need content inspection. The trade-off is that controls requiring access to information inside the TLS session will not receive the same visibility they would under deep inspection.

Why does deep inspection cause certificate warnings?

The FortiGate presents a dynamically generated certificate to the client during the inspected session. If the client does not trust the CA that signs that certificate, the connection appears untrusted. This is why managed certificate distribution is a core deployment task. Installing trust manually on a few test machines is not a scalable production method for a large organisation.

Will deep inspection slow internet access?

Decryption, security inspection and re-encryption consume more processing resources than basic firewall forwarding, so capacity planning matters. The impact depends on the FortiGate model, TLS traffic mix, enabled profiles, session rates and utilisation. Buyers should compare the model’s SSL inspection performance with their real bandwidth rather than assuming the firewall throughput figure applies to decrypted traffic.

Do all users need the same inspection policy?

Usually not. Corporate-managed workstations may be good candidates for deep inspection, while guest networks, BYOD devices, infrastructure appliances or specialised application segments may need certificate inspection or targeted exemptions. Segmenting the policy by trust level and device ownership makes troubleshooting and governance much clearer.

Another frequent question is whether SSL inspection requires a separate license. The inspection mechanism is part of the FortiGate security policy framework, but the reason many customers enable deep inspection is to improve the visibility available to other security services. Web filtering, malware protection, IPS, application intelligence and other capabilities can depend on FortiGuard subscriptions and the chosen license bundle. A quotation should therefore separate the firewall model, subscription term and configuration service rather than presenting “SSL inspection” as a standalone license with one universal price.

Application breakage is another major concern. Modern browsers generally work well when the trusted CA is deployed correctly, but some mobile apps, financial applications, software updaters and custom services may pin certificates or expect a specific TLS handshake. Mutual-TLS systems are especially important to identify because the application itself uses client certificates as part of authentication. These cases need testing and may require exemptions. The exemption should be as narrow as possible and documented so the security team knows what traffic remains encrypted end to end.

Buyers also ask about TLS 1.3, QUIC, HTTP/3 and newer encrypted-client technologies because these protocols continue to evolve. Fortinet has added support and handling options across current FortiOS releases, but the exact behaviour depends on software version and inspection mode. For that reason, an implementation guide written for an older release should not be used as the only source for a current rollout. Confirm the installed FortiOS version and test modern browser and SaaS traffic in the pilot group.

The most useful information to send FourTeck is practical rather than theoretical: FortiGate model, FortiOS version, internet speed, number of managed endpoints, major business applications, current FortiGuard bundle, whether Active Directory or MDM is available for certificate deployment, and which traffic the organisation does not want decrypted. With those inputs, the team can help determine whether the requirement is primarily configuration, licensing, appliance sizing, certificate planning or a combination of these items.

Decision questions that prevent the wrong SSL inspection rollout

Should we use certificate inspection or deep inspection for normal web browsing?

Start with the control you need. If certificate and destination information is sufficient, certificate inspection may avoid the complexity of decryption. If malware, application or web controls need to examine information inside HTTPS, deep inspection can provide the required visibility. The decision can also differ by user group, so a mixed policy is often more practical than one global setting.

How do we know whether our FortiGate is large enough?

Compare the actual model’s published SSL inspection throughput with measured peak internet usage, then add headroom for the security profiles, session behaviour and expected growth. Do not size from user count alone. If the firewall is already running near its resource limits, expand testing cautiously or consider a model review before production-wide decryption.

What certificate should the FortiGate use for deep inspection?

The best choice depends on how endpoints are managed. A FortiGate-generated CA can work for controlled deployments, while larger organisations may prefer a certificate issued from their internal PKI so trust can be distributed through established systems. The CA private key must be protected, its lifecycle must be owned, and replacement procedures should be planned before expiry.

What should happen when an application stops working?

Do not immediately bypass an entire category or user network. Identify the destination and application, verify whether certificate pinning or mutual TLS is involved, confirm vendor guidance, and create the smallest suitable exception when interception is not supported. Record the owner and reason so exemptions can be reviewed later.

Can we enable it during normal working hours?

A limited pilot may be possible during business hours, but a broad production change should follow the customer’s change-control process. Certificate trust should be deployed before the policy is activated, test users should be identified, critical applications should be validated, and rollback conditions should be agreed. The appropriate maintenance window depends on the environment and scope.

What should we send for an accurate UAE quotation?

Share whether you already own the FortiGate, the exact model, current FortiOS, subscription status, internet bandwidth, user and endpoint count, required inspection scope, certificate-management method, major applications, preferred deployment date and whether remote or on-site assistance is required. This lets FourTeck separate hardware, subscription, renewal and configuration items correctly.

Frequently asked questions

What is the difference between FortiGate certificate inspection and deep inspection?

Certificate inspection checks SSL/TLS connection and certificate information without decrypting the payload. Deep inspection decrypts the session so enabled security controls can inspect content before the FortiGate re-encrypts and forwards the traffic.

Does deep inspection require a trusted certificate on every endpoint?

Endpoints that are subject to deep inspection need to trust the CA used by the FortiGate, otherwise browsers or applications can report certificate errors. How that trust is distributed depends on the organisation’s endpoint-management and PKI design.

Can deep inspection affect FortiGate performance?

Yes. Decryption and re-encryption add processing work, and the final load also depends on the security profiles applied to the decrypted traffic. Use model-specific SSL inspection throughput and real traffic measurements for sizing.

Why do some applications fail while browsers continue to work?

Some applications use certificate pinning, mutual TLS or specialised TLS implementations that reject interception. Test business applications during a pilot and create controlled exemptions only where necessary.

Is FortiGate SSL Inspection a separate license?

The inspection profile is part of FortiGate policy functionality, but the web, malware, application, intrusion or other security services that use the resulting visibility may depend on FortiGuard subscriptions. Confirm the exact bundle for the required controls.

Can we exclude banking, health or other sensitive traffic?

FortiGate supports SSL inspection exemptions, but the correct categories and destinations should follow the organisation’s privacy, legal and business policies. Exemptions should be documented and reviewed.

Does FortiGate support modern TLS, HTTP/2, HTTP/3 and QUIC inspection?

FortiOS has current capabilities for modern encrypted protocols, but behaviour is version, inspection-mode and configuration dependent. Confirm the specific FortiOS release installed on the target FortiGate before relying on a feature.

Can FourTeck configure SSL inspection on an existing FortiGate?

FourTeck can review an existing FortiGate requirement and provide configuration assistance depending on model, FortiOS release, license status, access, application scope and the agreed support service. A pilot and backup plan are recommended before broader changes.

What information is needed to request a quote in Dubai?

Share the FortiGate model if already installed, FortiOS version, license status, internet bandwidth, user count, required inspection scope, endpoint-management method, application concerns and whether new hardware, renewal, remote support or onsite work is required.

Plan the inspection policy before changing production traffic

Share your FortiGate model, FortiOS version, internet bandwidth, subscription status, managed endpoint count and inspection objective. FourTeck can help review sizing, certificate strategy, exemptions, configuration scope and current UAE quotation options.

Scroll to Top
Powered by Joinchat