Fortinet uses digital certificates privacy and authentication.
Security Profile > SSL/SSH Inspection
Select Multiple Clients Connecting to Multiple Servers
Select SSL Certificate Inspection
Security Profile > SSL/SSH Inspection
Select Multiple Clients Connecting to Multiple Servers
Select Full SSL Inspection
Select CA certificate: Fortinet_CA_SSL
Security Profile > SSL/SSH Inspection.
Allow, block or ignore actions for untrusted certificates
This option is available if Multiple Clients Connecting to Multiple Servers.
Allow will send the browser an untrusted temporary digital certificate
Block will block the connection to the server with the untrusted certificate
Ignore uses a trusted FortiGate certificate to replace the certificate, when the server certificate is untrusted.
Except traffic for legal reasons
Except traffic based on web category
Go to, Security Profiles > SSL/SSH Inspection > Exempt from SSL Inspection (choose web categories or addresses)
FortiGate can check whether a certificate is valid or not.
To customized the check actions, Security Profiles > SSL/SSH Inspection > under Invalid SSL Certificate