Rather than manually listing every FQDN belonging to third-party software-update and SaaS vendors the NOC relies on, an administrator wants FortiGate to exempt whole categories of well-known, low-risk destinations from SSL deep inspection. What FortiGate capability supports this without hand-building a custom address list for every vendor?
Select an answer to reveal the explanation.
Short Explanation
Nobody wants to hand-type every software vendor's domain into an exemption list one at a time. FortiGate's SSL exemption list lets an admin pick from FortiGuard-maintained categories of destinations instead, covering a whole class of low-risk vendors in one entry. That's the tool built specifically for this kind of category-level exemption, rather than address control.
Full Explanation
The SSL/SSH inspection profile's exemption list supports entries beyond individual addresses and FQDNs — it can also reference FortiGuard-provided categories, letting an administrator exempt an entire class of well-known destinations from deep inspection in a single entry rather than maintaining a hand-built list of every vendor's domains. That directly answers the requirement of avoiding per-vendor address management while still keeping deep inspection active for everything else on the policy. Application control signatures identify and can restrict specific applications by their traffic patterns, but they are not the mechanism that controls whether SSL decryption happens — that decision is made in the SSL inspection profile, not the application-control profile. SD-WAN performance SLA health checks monitor link quality toward configured servers for routing-decision purposes and have no relationship to whether a session is decrypted. Static route metrics influence path selection in the routing table and have no bearing on content-inspection decisions at all; a higher-priority route does not bypass any security profile. As an operational check, review the SSL/SSH inspection profile's exemption configuration to confirm which built-in categories are selected and validate that sessions to sample vendor domains within those categories are passing without deep-inspection certificate substitution.