Skip to main content
cmoro
New Member
December 12, 2019
Question

FortiClient SSL VPN - DTLS only with SHA1

  • December 12, 2019
  • 3 replies
  • 5756 views

Hello,

 

due to performance issues and higher latency, I wanted to enable DTLS for FortiClient SSL VPN. Although I have configured everything as required, a VPN tunnel via UDP/443 was not established.

 

Then I have found out a root of the problem. When DTLS is enabled in the FortiClient EMS profile, FortiClient offers cipher suits (all with SHA1) which are not allowed on Fortigate. For that reason is the session terminated.

When I remove SHA as a banned-cipher, see below: config vpn ssl settings

set tlsv1-0 disable set tlsv1-1 disable set tlsv1-2 enable set dtls-tunnel enable

set banned-cipher DH CAMELLIA 3DES STATIC Then a TLS and subsequently a DTLS session are being established with the following cipher suits: [319:FortiClient:ecc]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 [310:FortiClient:ecf]DTLS established: DTLSv1 ECDHE-RSA-AES256-SHA

 

As we do not want to enable SHA1, is there any way how to push FCT to use SHA2 even for DTLS?

 

Enviroment

FCT 6.0.8, Windows 10

FGT 6.0.5

EMS 6.0.8

 

Thank you for any hint.

 

Regards,

Jozef

    3 replies

    emnoc
    New Member
    December 12, 2019

    I see this exact behavior also, did you open a ticket and are you on the latest fortiOS version(s0?

     

    Ken Felix

    cmoro
    cmoroAuthor
    New Member
    December 12, 2019

    Yes, I have opened a ticket and waiting for feedback from the tac engineer.

    FortiClient runs on the latest 6.0.8 version.

    emnoc
    New Member
    December 12, 2019

    Good , I believe the forticlient version plays a major issue at hand also. I realize I wrote tidbit about  DTLS and FC and the support is getting much better.

     

    http://socpuppet.blogspot.com/2017/09/dtls-forticlient-fortios-v54.html

     

    Ken Felix

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!