Jump to content

Recommended Posts

Posted
Hi, we have moved over to Fortinet for our filtering and certificates need installing to have access to the Internet. This has been done via a group policy for PC'S and laptops and is working fine. The problem is our head wants anyone who uses a device in school eg. Mobile phones or personal laptops to only do do when connected to our WiFi so we can keep a check on searches etc. Our technicians have managed to sort out how to install the certificate on an iPhone but not an Android device. Can anyone help? Plus, what happens when Ofsted come in and want to connect to the WiFi? They would not be able to get access to the Internet without the certificate. We have been told to set up another WiFi logon with some static ip addresses but have been unable to sort as of yet. Hope this makes sense and that someone can help? Apparently, no other school have said there is an issue apart from ours! Thanks
Posted

For a web filter to be any use now it needs to be able to inspect HTTPS traffic, any devices that are going to have traffic inspected need to have this certificate installed on them so they trust the web filter.

 

Here's a guide for installing certificates on Android devices:

https://support.securly.com/hc/en-us/articles/212869927-How-do-I-install-Securly-SSL-certificate-on-Android-device-

Substitute their certificate for yours

 

One option is to setup a separate WiFi network with a different address range and then tell the Fortinet not to apply HTTPS inspection to that range. This would allow users without the certificate installed to connect to the internet, however the filtering for these devices would effectively be non existent. This is our standard practice, we leave it up to the school whether they use this WiFi network or not.

  • Thanks 1
Posted

We had similar with an old system

 

Even installing the certificates on Android didn't fully work. But having severally limited resources never got to look at it further.

Posted

My impression is that Google don’t like the MITM certificate. You probably spend a lot of time putting domains in an exception list due to MITM breaking apps in Android and iOS. Even without MiTM the fortinet can check domains and block known bad domains.

 

The filtering needs to move to browser extensions really. Not possible on Android and iOS though.

Posted
My impression is that Google don’t like the MITM certificate. You probably spend a lot of time putting domains in an exception list due to MITM breaking apps in Android and iOS. Even without MiTM the fortinet can check domains and block known bad domains.

 

The filtering needs to move to browser extensions really. Not possible on Android and iOS though.

 

Lots of the big sites use certificate pinning or suchlike to prevent MITM attacks. Which is what traditional SSL inspection is doing, albeit we don't call it a MITM attack because we're doing it with good intentions.

 

This problem is only going to get worse imo, I think you'll need a product that installs an agent on EUC devices in the future if you want to continue to monitor their traffic...

Posted
We have a guide for each device: Windows, Chrome, IOS and Android. Android is always a pain as it depends on the version they are running. We have a separate wifi SSID for external people that come in that we regularly change the password to.
Posted
You can set Fortinet to bypass filtering for certain groups, so question is how do you identify the groups, they're on a different SSID, so could do different IP range, or VLAN for example

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...