Increasing SSL VPN Security (SSL Minimum Protokoll Version)
Dear Fortinet Community.
I have a question regarding the "hardening" of SSL VPN connections. I would like to increase the security by increasing the minimum TLS protocol version.
Last week I have tried this via CLI. Just to let you know. After the change I could not login to SSL VPN anymore. But I could switch back to the old configuration and then it worked again.
What did I do? I have used this command on cli:
config vpn ssl setting
set ssl-min-proto-ver tls1-2
end
After the change via cli my config looked different. The line that shows the minimum protocol version just disapeard. When using the Fortinet VPN Client it stopped the connection at 40%. Did I do something wrong? Have I missed something? Probably some of you have done this in your environment and can explain me what to do in order to use a higher TLS version.
FYI: we use tunnel-mode. Fortigate is on newest version 7.2.4. I can confirm that TLS 1.3 should be possible.
These are our vpn ssl settings. I have removed informations for security reasons.

I would be super happy for any kind of help so that I can understand why I could not connect after my change. :)
Have a wonderful day.
With kindest Regards
FortiLover
