Create SSL/SSH Inspection Profile on FortiGate
Secure Sockets Layer (SSL) content scanning and inspection enables web filtering and antivirus scanning in FortiGate. There are already pre-existing SSL profiles in FortiGate. However a custom SSL profile need to be used in preparation for the IPS Sensor creation.
- Log into FortiGate.
- Go to Security Profiles > SSL/SSH Inspection.
- Create a new SSL/SSH inspection profile called "deep-test".
- Keep the default configurations and scroll down to SSH Inspection Options.
- Turn on SSH deep scan.
- In Common Options > Invalid SSL certificates, click Allow.
- Click OK to finish.