CCleaner Cloud and Fortigate

There is a known issue with CCleaner Cloud if SSL Full inspection is enabled within Fortigate. Please find a solution below:

Issue

After enabling full SSL inspection on the normal outgoing traffic policy on Fortigate; CCleaner Cloud agents could not connect to the cloud service.

Information

For CCleaner Cloud to connect, it needs access to port 443, and port 8080. Additionally, it needs to be able to communicate with the following domains:

  1. ms4.agomo.com
  2. dl.ccleanercloud.com
  3. ms.agomo.com
  4. ms3.agomo.com
  5. ds.agomo.com
  6. www.agomo.com
  7. www.ccleanercloud.com
  8. speccy.piriform.com
  9. agomo.com
  10. ccleanercloud.com
  11. piriform.com

Resolution

  1. Create an address for each of the URLs provided. You can place the addresses into a group if you like.
  2. Then exempt those addresses in the SSL Inspection Profile that is being used for the Policy.
  3. Make a copy of the policy being used for normal outgoing traffic.
  4. Paste the copy above the normal outgoing traffic policy.
  5. Edit the copy and name it something like “Bypass SSL Inspection”.
  6. In the "Destination" field add the “SSL Full inspection exemption” list you created above.
  7. Remove all other addresses from the Destination field.
  8. Set the SSL Inspection profile to a profile that does not perform Full packet inspection. Click OK.
  9. Enable the policy.
  10. Now traffic that is destined for the URLs in the exemption group will not have the Full packet scan performed but all other traffic will continue to be fully inspected.

Need further help?