Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Umesh
Contributor

TLS 1.2 and 1.3 query at Fortigate Firewall

Dear Team,

 

One of our server team has report they are not able to access website - like abc.com using curl command. 

 

Earlier  server team used to access this website using tls 1.2 now they have changed from 1.2 to 1.3 tls version.

 

after changing tls 1.3 they are facing error like ssl handshake error when they try to access website using curl command.  

 

So my query is do we have to enable TLS 1.3 at Fortigate firewall or not.

 

Please refer the diagram for example.

 

tls.JPG 

 

I would apricate your response.

 

Thank you.

6 REPLIES 6
AEK
SuperUser
SuperUser

Hello Umesh

  • Do you have any error message from client side when trying to access the site?
  • Do you see any SSL errors on FortiGate (enable Log SSL anomalies in the used SSL profile, then check under Logs & Report > SSL)
  • Can you try switch your related firewall policy from flow based to proxy based?
AEK
AEK
ozkanaltas
Contributor III

Hello @Umesh ,

 

If abc.com doesn't support TLS 1.3 you can't access with TLS 1.3 to that website. You can learn the supported TLS version of the remote website with this tool.

 

https://www.ssllabs.com/ssltest/

 

Normally, you don't need to change anything on FortiGate.

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Umesh
Contributor

Do we have to change at firewall TLS 1.3 , If server team has changed TLS 1.3 at server.

 

Note - we are not using SSL VPN and no SSL certificates at firewall.

 

ozkanaltas

Hello @Umesh ,

 

As per your scenario, no need to make any changes to FortiGate. Did you test the remote web site for this tool as I mentioned? 

 

https://www.ssllabs.com/ssltest/

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Umesh
Contributor

Yes, I have checked.

 

abc.com - using TLS 1.2 and TLS 1.3 both.

smaruvala
Staff
Staff

Hi,

 

- What is the error being observed? 

- Is it seen for a specific website? If its a public website can you provide the URL?

- Which state of the SSL handshake is having issue? Packet capture can help here?

- Are you using SSL Inspection in the Policy?

- Is the Kyber key exchange used while accessing this website?

 

Regards,

Shiva

 

 

Labels
Top Kudoed Authors