Description |
This article describes how to check the TLS version negotiated by a client machine trying to connect to an SSL VPN using FortiClient.
Even running the debug for SSL VPN on the FortiGate, will show an 'unsupported protocol' for the connection that the client machine is trying to initiate.
|
Scope | FortiGate. |
Solution |
To check the TLS version negotiated by the client machine, Perform packet capture on FortiGate's external interface where it accepts SSLVPN connections
From GUI: Go to Network -> Packet Capture and select 'Create new'. Filter the interface and the port used by SSL VPN.
The TLS version is shown after.
|
-