| Description | This article describes how to block insecure TLS/SSL connections. |
| Scope |
FortiGate, FortiProxy. |
| Solution |
By default, FortiGate (up to v7.0.4)/FortiProxy will allow TLS 1.0 (or SSL) via SSL certificate or deep inspection. It is possible to block insecure TLS/SSL connections via the command 'set unsupported-ssl block'.
Here is an example:
Note:
config firewall ssl-ssh-profile end Related article: Technical Tip: Difference between min-allowed-ssl-version and unsupported-ssl-version in firewall ss...
config firewall policy
Related documents SSL traffic over TLS 1.0 will not be checked and will be bypassed by default Technical Tip: How to block lower TLS version for pass-through traffic |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.