Description | This article describes how to block insecure TLS/SSL connections. |
Scope |
FortiGate, FortiProxy. |
Solution |
By default, FortiGate (up to v7.0.4)/FortiProxy will allow TLS 1.0 (or SSL) via SSL certificate or deep inspection. It is possible to block insecure TLS/SSL connections via the command 'set unsupported-ssl block'.
Here is an example:
Note:
config firewall ssl-ssh-profile end Related article: Technical Tip: Difference between min-allowed-ssl-version and unsupported-ssl-version in firewall ss...
config firewall policy
Related documents SSL traffic over TLS 1.0 will not be checked and will be bypassed by default Technical Tip: How to block lower TLS version for pass-through traffic |