Skip to main content
Kiwi
New Member
February 3, 2020
Question

Fortigate-VM Evaluation copy. Can't test SSL VPN Client setup

  • February 3, 2020
  • 10 replies
  • 18764 views

Hello

 

I installed FortiGate-VM v 6.2 and 5.6.9 (Both Evaluation Copies) on VMware Workstation.

As instructed in multiple tutorial videos (Cookbook and Youtube), I configured SSL VPN on them to test client access.

 

Problem-1: When trying to test the SSL VPN functionality https://<external_IP>:10433 is fails with error like SSL_ERROR_NO_CYPHER_OVERLAP  (Firefox) or similar error message about SSL version mismatch when using other browsers.

 

- I know, evaluation copies have some limitation, like Low encryption only (no HTTPS administrative access)

- Some threads talk about using old Web browsers for TLS version to overcome the problem.

  I tried to enable TLS 1.0 ans SSL 2.0 in IExplorer ver 7 that come with Windows XP,  it did not help!

 

[style="background-color: #ffff99;"]Question:[/style] Any idea, whether it's possible or not at all to test SSL VPN Client with evaluation copies ?

 

Problem-2: After installing an Offline version of FortiClient VPN it keeps asking for Certificate.

                 I am not a customer and I do not have Certificates for that, just home Lab. How to bypass this issue for testing                  purposes ?

 

Thank you

    10 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    February 3, 2020

    Did you check your Firefox TLS settings?

    https://knowledge.digicert.com/generalinformation/INFO3299.html

    The max/min values are explained below:

    [link]http://kb.mozillazine.org/Security.tls.version.*[/link]

     

    On the other hand, my 50E running 6.2.3 shows the default SSL encryption settings are:

    xxx (settings) # get

    <snip>

    ssl-max-proto-ver      : tlsl-3

    ssl-min-proto-ver       : tlsl-2

     

    They need to overlap.

     

    Kiwi
    KiwiAuthor
    New Member
    February 3, 2020

    Thank you Toshi for your reply.

    In the mean time I updated my initial posting about the TLS 1.0 details before I saw your reply, so have a look again to my posting and comment again.

    Toshi_Esumi
    SuperUser
    SuperUser
    February 3, 2020

    What's your settings at the FGT-VM side under "config vpn ssl settings" then just "get", which would show you all settings?

    And you must have configured, or by default, to enable "Require Client Certificate" (in cli, "set reqclientcert enable"). Just disable it.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.