Created on
10-30-2025
10:20 AM
Edited on
11-26-2025
08:00 AM
By
Stephen_G
| Description | This article describes additional information about the 'legacy-auth-mode' setting and certificate on OFTP connection checking on FortiAnalyzer. |
| Scope | FortiAnalyzer v7.4.7+, v7.6.3+. |
| Solution |
In the FortiAnalyzer v7.4.8 Release Notes, the 'Special Notices' section states that FortiAnalyzer checks the SN information against the Common Name of the Certificate for the OFTP connection.
Check details here: legacy-auth-mode command added
What’s New in FortiAnalyzer 7.4 What’s New in FortiAnalyzer 7.6
Note: The config legacy-auth-mode is useful when FortiAnalyzer integrates with FortiMail, FortiWeb, and FortiEMS. This is due to these products continuing to go down after FortiAnalyzer has been upgraded to the latest version. When enabling the legacy-auth-mode, the FortiAnalyzer will skip using the certificate (CN) and use the username and password to validate the connection.
It is very important to note that this mode should only ever be enabled if the OFTP port (UDP and TCP 514) is not exposed or if access controls are in place.
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.