Created on 08-16-2019 01:49 AM Edited on 04-06-2022 11:23 AM By Anonymous
Description
This articles explains how the HSTS parameter max age for SSL VPN portal is not configurable in FortiGate, regardless of the firmware, and the available options are as follows.
Solution
Since FortiOS 5.4.8 and FortiOS 5.6.4 HSTS support is added and enforced. (469037)
Then, max-age value was increased to one year starting with FortiOS 5.4.10, 5.6.5 and 6.0.1 (472195) to match certain security standard ratings.
Since the existing RFCs are not stating how long this "long time" should be, a longer time is considered to be better. The max-age parameter is not user-configurable in any of the FortiOS versions to date.
The available choices are:
- 1year for the firmware versions above (or newer)
- 6months for older versions of each branch of firmware.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.