FortiGate Deep Packet Inspection (SSL Decryption) Explained + Full Configuration Guide (with PKI)
Welcome back. In this video, I break down Deep Packet Inspection (DPI) and SSL decryption on a FortiGate firewall. I explain what it is, why it matters, and how to configure it step-by-step. I also included some real world use cases that you can implement in your network once DPI is configured and working. I have timestamps below so you can skip around. I start with a simple explanation of how encrypted vs unencrypted traffic works, and why SSL inspection is critical for modern network security. Then we move into a full FortiGate configuration demo. Agenda: What Deep Packet Inspection (DPI) is and how SSL decryption works Why SSL inspection is required for full visibility and security Configuring SSL/SSH inspection profiles on a FortiGate Using the built-in FortiGate CA certificate for quick deployment Demonstrating security features enabled by DPI: Antivirus inspection Web filtering (including keyword/content filtering) Application control Handling real-world challenges (certificate pinning, exemptions, etc.) Creating and using your own PKI (Sub CA) for SSL inspection Exporting certificates and importing them into FortiGate Deploying trusted certificates to endpoints By the end of this video, you should have a decent understanding of how DPI works on a FortiGate, and how to configure it. If you have any questions, you can leave a comment and I will assist you! Timestamps: 0:00 Intro and Presentation 12:45 Built in SSL Inspection Profiles 13:38 Creating our own DPI profile 14:51 Inspection Excemptions 16:07 Firewall Policy 17:20 Configuring the Client 20:30 Use Case 1- AntiVirus Scanning 23:50 Use Case 2- Logging Searched Words 26:40 Use Case 3- Blocking Specfic Word Searches 28:22 Use Case 4- Safe Search Enforcement 29:15 Use Case 5 - Granular Application Control 34:41 Using Our Own Certificate via Windows PKI

Firewall Fundamentals Explained | Network Security for Beginners

THESE Apps Are SPYING on You — Shut Them Off NOW!

FortiGate (FortiOS 7.6) IPsec Dial-Up VPN with Microsoft Entra ID (SAML) for Remote Users

FortiGate HA + FortiSwitch MCLAG Configuration Guide | 2 Firewalls + 2 Switches

34- FortiGate + Active Directory LDAPS Setup for SSL VPN Access | Complete Guide 2026

The Problem with Welding

How to Track the People Tracking YOU

FortiGate Linux CLI Troubleshooting with fnsysctl- Disk, RAM, Interfaces, Processes, Sockets, NTurbo

FortiGate IPsec Dial-Up VPN for Remote Users + SSL VPN Migration

FortiGate NAC Demo: Built-In Wired + WiFi NAC (FortiGate + FortiSwitch + FortiAP)

What is DNS? (and how it makes the Internet work)

Wireshark Tutorial for Beginners | Network Scanning Made Easy

"Something Wicked This Way Comes" — Why The AI Bubble Isn't What You Think

How Nvidia GPUs Compare To Google’s And Amazon’s AI Chips

FortiGate Authentication Config & Demo: Active vs Passive Auth, FSSO, and Firewall Policies

Attacking AI - Jason Haddix - NDC Security 2026

Do VPNs Really Protect Privacy? Data & Cybersecurity Insights

Palantir. IT’S WORSE Than You Think

Programable Logic Controller Basics Explained - automation engineering

