SSL inspection for clients connecting from the Internet to the server behind the USG FLEX 500

Options
Kv3
Kv3 Posts: 19 image  Freshman Member
First Comment Friend Collector Seventh Anniversary

Hello,
has anyone managed to set up a working SSL inspection for clients connecting from the Internet to the server behind the USG FLEX 500?

I have an IIS server in the local network accessible from the Internet and I'm trying to set up SSL inspection for it.
I uploaded the same SSL certificate to the USG as on the server (Let's Encrypt). In Trusted Ceritificates I have root and intermediate Let's Encrypt certificates. If I open the certificates, I see "Validation Result=successful".
In SSL Inspection I have a Profile with a Let's Encrypt certificate and the profile is set in the security policy.

If I try to view pages from the server on a client computer browser on the Internet, it reports an error: ERR_CERT_AUTHORITY_INVALID

In the USG log it is: SSL version: 0x0304, CN = xxx.zzzzzzz.cz, cert key = RSA-2048

Can anyone advise me, please?

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,669 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Kv3

    Regarding your description, it seems like you set the SSL inspection to a WAN to LAN policy. Please note that SSL inspection usually be set with LAN to WAN policy to protect client's traffic. It is recommended to disassociate the SSL Inspection with the security policy.

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 4,446 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    I think for SSL inspection to work the client needs the certificate in their trusted root certification