Configure SSL Inspection and Certificate Pinning Exemptions on a FortiGate
This guide turns on SSL/TLS deep inspection on a FortiGate and then adds exemptions so that applications using certificate pinning (banking apps, Dropbox, Windows/Apple update services, and similar) keep working instead of failing silently. Deep inspection is a man-in-the-middle: the FortiGate decrypts HTTPS, scans it, and re-signs it with its own CA. That is powerful and also the single most disruptive thing you can enable on a firewall.













