Skip to main content
dingjerry_FTNT
Staff
Staff
October 30, 2025

Technical Tip: Additional information about the 'legacy-auth-mode' setting and certificate on OFTP connection checking on FortiAnalyzer

  • October 30, 2025
  • 0 replies
  • 1529 views
Description This article describes additional information about the 'legacy-auth-mode' setting and certificate on OFTP connection checking on FortiAnalyzer.
Scope FortiAnalyzer v7.2.10+, v7.4.7+, v7.6.3+.
Solution

In the FortiAnalyzer v7.4.8 Release Notes, the 'Special Notices' section states that FortiAnalyzer checks the SN information against the Common Name of the Certificate for the OFTP connection. 

 

Check details here:

legacy-auth-mode command added

 

  1. The 'legacy-auth-mode' setting was introduced in FortiAnalyzer v7.2.10 GA, FortiAnalyzer v7.4.7 GA and FortiAnalyzer v7.6.3 GA.

What’s New in FortiAnalyzer 7.2 

What’s New in FortiAnalyzer 7.4 

What’s New in FortiAnalyzer 7.6 

 

  1. The certificate used for the OFTP connection can be the Fortinet default ones or a customized one. If a customized certificate is in use, the SN in the Common Name field must be the device’s genuine serial number, not a fabricated one.
    1. To change the certificate for OFTP connection on FortiAnalyzer, use the 'config system certificate oftp' command.
    2. To change the certificate for OFTP connection on FortiGate, use the 'config log fortianalyzer setting' command.

 

Note:

The config legacy-auth-mode is useful when FortiAnalyzer integrates with FortiMail, FortiWeb, FortiEMS and FortiProxy. This is due to these products continuing to go down after FortiAnalyzer has been upgraded to the latest version. When enabling the legacy-auth-mode, the FortiAnalyzer will skip using the certificate (CN) and use the username and password to validate the connection.

 

Note:

For FortiAnalyzer integration with FortiProxy versions 7.4.9 or 7.6.3 and later, enabling legacy-auth-mode is not needed.

 

It is very important to note that this mode should only ever be enabled if the OFTP port (UDP and TCP 514) is not exposed or if access controls are in place.

 

Related documents:

certificate oftp

config log FortiAnalyzer setting

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!