FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
gonzalezw
Staff
Staff
Article Id 307182
Description This article describes that the Dropbox desktop app does not work when Deep Inspection is enabled on the FortiGate Firewall Rule.
Scope FortiGate and Windows OS.
Solution

When installing the Dropbox desktop app on a Windows machine, with deep inspection enabled in the firewall policy from LAN to WAN, Dropbox may fail to function. The desktop app does not open or continuously spin without displaying the login screen.

 

This behavior is typically due to Full SSL inspection being enabled. For more information on the differences between SSL Certificate Inspection and Full SSL inspection, refer to this related article:

Technical Note: Differences between SSL Certificate Inspection and Full SSL Inspection

 

The Dropbox team recommends whitelisting a list of domains in FortiGate. It is possible to find the list of official Dropbox domains here: https://help.dropbox.com/security/official-domains us

 

To whitelist these domains in the SSL INSPECTION security profile under 'Exempt from SSL Inspection', follow these steps:

 

  1. Create  addresses objects using the Dropbox Domain list https://help.dropbox.com/security/official-domains  as FQDN:


dropbox2.png

 

  1. Once each object individually have been created, add them into a single group:

 

dropbox3.png

 

  1. Now that the address group is created, the deep inspection profile will be cloned since the default profile cannot be edited:

 

dropbox4.png

 

  1. Add the group created above to the 'Exempt from SSL Inspection' in the 'SSL/SSH inspection' of the 'Clone of deep-inspection' profile under 'Security Profile' in the firewall.

 

dropbox5.png

 

  1. Select 'OK' to save the changes. Test again on the Windows computer.
Contributors