Technical Tip: Additional information about the 'legacy-auth-mode' setting and certificate on OFTP connection checking on FortiAnalyzer
| Description | This article describes additional information about the 'legacy-auth-mode' setting and certificate on OFTP connection checking on FortiAnalyzer. |
| Scope | FortiAnalyzer v7.2.10+, v7.4.7+, v7.6.3+. |
| Solution | In the FortiAnalyzer v7.4.8 Release Notes, the 'Special Notices' section states that FortiAnalyzer checks the SN information against the Common Name of the Certificate for the OFTP connection.
Check details here: legacy-auth-mode command added
What’s New in FortiAnalyzer 7.2 What’s New in FortiAnalyzer 7.4 What’s New in FortiAnalyzer 7.6
Note: The config legacy-auth-mode is useful when FortiAnalyzer integrates with FortiMail, FortiWeb, FortiEMS and FortiProxy. This is due to these products continuing to go down after FortiAnalyzer has been upgraded to the latest version. When enabling the legacy-auth-mode, the FortiAnalyzer will skip using the certificate (CN) and use the username and password to validate the connection.
Note: For FortiAnalyzer integration with FortiProxy versions 7.4.9 or 7.6.3 and later, enabling legacy-auth-mode is not needed.
It is very important to note that this mode should only ever be enabled if the OFTP port (UDP and TCP 514) is not exposed or if access controls are in place.
Related documents: |
