Skip to main content
yfourar
New Member
June 8, 2021
Question

SSL alert sent

  • June 8, 2021
  • 2 replies
  • 5225 views

Hello, after I upgraded my FortiOS version to 6.0.12 I receive these alerts in eventlogging

Message meets Alert condition date=2021-06-07 time=17:49:59 devname=rinxcomfw1 devid=FGT60XXXXXX logid="0105048039" type="event" subtype="wad" level="error" vd="root" eventtime=1623080999 logdesc="SSL fatal alert sent" session_id=242277 policyid=1 srcip=X.X.X.X srcport=X dstip=X.X.X.X dstport=443 action="send" alert="2" desc="illegal parameter" msg="SSL Alert sent" Message meets Alert condition date=2021-06-07 time=17:49:59 devname=rinxcomfw1 devid=FGT60DXXXXXX logid="0105048003" type="event" subtype="wad" level="error" vd="root" eventtime=1623080999 logdesc="SSL handshake length invalid" session_id=242277 policyid=1 srcip=X.X.X.X srcport=X dstip=X.X.X.X dstport=443 action="close" handshake="ClientHello" msg="Bad length in SSL hands

The policy ID 1 is the internet access & I use cetificate inspection.

Anyone seeing the same thing or knowns what kind of traffic is causing these alerts?

    2 replies

    tzepf
    New Member
    September 24, 2021

    Any news on this? Same behaviour with me after Upgrading to 6.4.7 - i use SD WAN with Volume based load balancing and SSL Inspection...

     

    Is this a concern or can i ignore those?

    Tedkaznj
    New Member
    July 19, 2022

    Did you check if these are users using browser with broken TLS?

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!