Created on 06-27-2022 08:04 AM Edited on 08-27-2024 06:20 AM By Jean-Philippe_P
Description | This article describes how to control insecure ciphers entering the network through explicit DoT and DoH traffic. |
Scope | FortiGate. |
Solution |
On FortiOS 7.0, 'ssl-ssh-profile' added 'min-allowed-ssl-version' per protocol, and it's applied to DoT and DoH. This option limits the minimum allowed SSL version but 'ssl-ssh-profile' does not have control to filter static key ciphers.
Hence the following global commands were introduced to control explicit DoT handshake in 7.0.6 and 7.2.0 onward.
config system global
DoT can use a pre-filtered cipher list now. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.