Skip to main content
NeilG
New Member
December 27, 2019
Question

Anyone having connection timeout errors with deep inspection on Chromium dev?

  • December 27, 2019
  • 4 replies
  • 5931 views

So I think the "TLS 1.3 downgrade hardening bypass" is breaking with FortiOS 5.6.x Deep inspection, even if a url is on the SSL inspection exception list.

https://www.chromestatus....ature/5128354539765760

 

 

Question: Is there a build of 5.6.x that has good TLS 1.3 deep inspection support? I am currently on FortiOS v5.6.9 build1673, and am trying to determine if upgrading to 5.6.12 would help or hurt.

 

Thanks!

 

-Neil

    4 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    December 28, 2019

    I heard they started fully supporting TLS 1.3 with 6.2.

    https://www.fortinet.com/blog/business-and-technology/tls-is-here-what-this-means-for-you.html

    I'm not sure if they would implement the same even to 6.0.

    James_G
    New Member
    December 28, 2019
    Correct, TLS 1.3 is a fortios 6.2 and higher feature. It is the feature that I feel will make many people eventually upgrade to 6.2.x.
    NeilG
    NeilGAuthor
    New Member
    December 30, 2019

    Based on googles current chromium schedule, the v80 code line goes live in Feb 2020... 

     

    https://www.chromium.org/developers/calendar

    https://chromiumdash.appspot.com/schedule

     

    How are people not freaking out about this not working pre-6.2?

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.