{{ secondMenu.name }}
FortiGate Parameter
FortiGate Parameter Description
Corresponding Sangfor NGAF Module/Parameter
Migration Notes
name
Policy template name
Policies > Decryption
The name can be kept consistent
inspect-all
Whether to inspect all SSL traffic deeply
Typically used for enterprise-wide HTTPS control
caname
Issuing intermediate CA certificate
Not supported
untrusted-caname
For issuing untrusted certificates
untrusted-cert
How to handle untrusted certificates
expired-cert
How to handle expired certificates
cert-validation-timeout
Validation timeout behavior
client-cert-request
Client certificate request policy
ssl-exemptions
SSL exemption addresses/domains
ssl-algorithm
Allowed encryption strength
server-cert-validation
Whether to validate server certificate chain
supported-versions
Supported SSL/TLS protocol versions
NGAF supports TLS 1.0–1.3
ssh-policy
SSH traffic inspection mode
log-invalid-cert
Whether to log certificate exceptions
ssl-allow-ssl-v3
Whether to allow SSLv3