Resolving SSL Deep Inspection Issues with Self-Signed Certificates
A FortiGate administrator is troubleshooting an issue where users cannot access an internal HTTPS server (10.10.10.10:443) after enabling SSL deep inspection. The administrator sees that the server's certificate is self-signed. Which TWO actions should the administrator take to allow access while maintaining inspection?
Quick Answer
The answer is to add the server’s IP address to the SSL/SSH profile’s exemption list. This is correct because SSL deep inspection cannot validate a self-signed certificate against a trusted Certificate Authority, causing the FortiGate to block the connection as untrusted. By exempting the server’s IP from inspection, traffic flows without decryption, while the alternative is to import the self-signed certificate as a trusted CA so deep inspection can validate it. On the Fortinet NSE 4 exam, this scenario tests your understanding of how deep inspection handles untrusted certificates—a common trap is assuming you must always inspect everything, but the exemption list is the quick fix for internal servers. Remember the mnemonic “Self-Signed = Skip or Sign” to recall you either skip inspection via exemption or sign the certificate as trusted.
⚠ Common exam trap
It's easy for candidates to think disabling certificate validation (Option C) is a safe workaround, but it actually disables all certificate checks, which is a security risk and not the intended solution for trusting a specific self-signed certificate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Import the server's self-signed certificate into FortiGate's trusted CA list
Importing the server's self-signed certificate into FortiGate's trusted CA list allows the FortiGate to trust the certificate during SSL deep inspection, preventing certificate validation errors. Option E is correct because adding the server's IP to the SSL/SSH profile's exemption list bypasses inspection for that specific server, allowing access without deep inspection while still applying other security profiles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable deep inspection on the policy
Why it's wrong here
This would stop inspection for all traffic, which may not be desired.
- ✗
Change the policy action to DENY
Why it's wrong here
Denying access is not the goal; they want to allow access.
- ✗
Disable certificate validation in the SSL/SSH profile
Why it's wrong here
Disabling validation might allow the connection but would weaken security and is not recommended; it also does not fix the underlying certificate trust issue.
- ✓
Import the server's self-signed certificate into FortiGate's trusted CA list
Why this is correct
If FortiGate trusts the server's CA (or the certificate itself), it can establish the inspection without certificate errors.
- ✓
Add the server's IP address to the SSL/SSH profile's exemption list
Why this is correct
Exempting the server from inspection will allow access without certificate errors, but inspection is bypassed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate administrator receives reports that users cannot access a legitimate website that uses HTTPS. The web filtering profile is configured with strict FortiGuard categories and 'monitor all' for unknown sites. The firewall policy has an SSL/SSH inspection profile set to 'deep-inspection'. What is the most likely cause of the issue?
hard- ✓ A.The website uses a self-signed certificate which is not trusted by the FortiGate CA bundle
- B.The antivirus profile is blocking a file on the website
- C.The DNS filter is blocking the domain
- D.The website's FortiGuard category is set to 'block'
Why A: The most likely cause is that the website uses a self-signed certificate, which is not included in the FortiGate's trusted CA bundle. When deep inspection is enabled, the FortiGate acts as a man-in-the-middle and must validate the server's certificate against its CA store; a self-signed certificate fails this validation, causing the connection to be blocked. This is a common issue with strict inspection profiles that require trusted certificates.
Variation 2. A network administrator notices that users cannot access HTTPS websites after enabling SSL inspection. The firewall policy allows the traffic, and the certificate is trusted on the clients. What is the most likely cause?
medium- A.The CA certificate used for SSL inspection is not trusted by the clients.
- ✓ B.The client's browser has a proxy configured incorrectly.
- C.The firewall policy has SSL inspection disabled.
- D.The DNS server is not resolving the domain names.
Why B: If the client's browser has a proxy configured incorrectly, the traffic may bypass the firewall's SSL inspection. This can cause HTTPS access failures even though the CA certificate is trusted on the clients and the firewall policy allows the traffic. The firewall may not intercept the traffic if it goes through a proxy server that is not configured to apply SSL inspection.
Variation 3. An administrator configures SSL deep inspection with a CA certificate. Users accessing an internal site (internal.company.com) receive a certificate error. The administrator wants to avoid the error without disabling deep inspection. What should be done?
hard- A.Replace the CA certificate with a self-signed one
- B.Use certificate inspection instead of deep inspection
- C.Disable certificate validation in the deep inspection profile
- ✓ D.Add internal.company.com to the SSL/SSH inspection exemption list
Why D: Adding internal.company.com to the SSL/SSH inspection exemption list tells the FortiGate to bypass deep inspection for that specific site, allowing the internal CA certificate to be used without triggering a certificate error. This avoids the error while keeping deep inspection enabled for all other traffic, which is the administrator's goal.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.