Skip to main content
Umesh
Explorer II
May 16, 2024
Question

TLS 1.2 and 1.3 query at Fortigate Firewall

  • May 16, 2024
  • 5 replies
  • 3143 views

Dear Team,

 

One of our server team has report they are not able to access website - like abc.com using curl command. 

 

Earlier  server team used to access this website using tls 1.2 now they have changed from 1.2 to 1.3 tls version.

 

after changing tls 1.3 they are facing error like ssl handshake error when they try to access website using curl command.  

 

So my query is do we have to enable TLS 1.3 at Fortigate firewall or not.

 

Please refer the diagram for example.

 

tls.JPG 

 

I would apricate your response.

 

Thank you.

5 replies

AEK
SuperUser
SuperUser
May 16, 2024

Hello Umesh

  • Do you have any error message from client side when trying to access the site?
  • Do you see any SSL errors on FortiGate (enable Log SSL anomalies in the used SSL profile, then check under Logs & Report > SSL)
  • Can you try switch your related firewall policy from flow based to proxy based?
AEK
ozkanaltas
Valued Contributor III
May 16, 2024

Hello @Umesh ,

 

If abc.com doesn't support TLS 1.3 you can't access with TLS 1.3 to that website. You can learn the supported TLS version of the remote website with this tool.

 

https://www.ssllabs.com/ssltest/

 

Normally, you don't need to change anything on FortiGate.

 

 

Umesh
UmeshAuthor
Explorer II
May 16, 2024

Do we have to change at firewall TLS 1.3 , If server team has changed TLS 1.3 at server.

 

Note - we are not using SSL VPN and no SSL certificates at firewall.

 

ozkanaltas
Valued Contributor III
May 16, 2024

Hello @Umesh ,

 

As per your scenario, no need to make any changes to FortiGate. Did you test the remote web site for this tool as I mentioned? 

 

https://www.ssllabs.com/ssltest/

 

Umesh
UmeshAuthor
Explorer II
May 16, 2024

Yes, I have checked.

 

abc.com - using TLS 1.2 and TLS 1.3 both.

smaruvala
Staff
Staff
May 16, 2024

Hi,

 

- What is the error being observed? 

- Is it seen for a specific website? If its a public website can you provide the URL?

- Which state of the SSL handshake is having issue? Packet capture can help here?

- Are you using SSL Inspection in the Policy?

- Is the Kyber key exchange used while accessing this website?

 

Regards,

Shiva