Created on
01-05-2023
12:05 AM
Edited on
01-05-2023
01:16 AM
By
Anthony_E
| Description | The article describes how to verify TLS 1.0 is disabled in the FortiGate administrative access. |
| Scope | FortiGate. |
| Solution |
If there is a security scanning tool try to scan FortiGate interface IP, it is possible to capture the packet by running command below:
# diagnose sniffer packet any "host <ip address>" 6 0
<ip address> is the scanning tool's IP address.
Convert the output into .pcap format, and apply the filter using 'tls.record.version == 0x0301'. It will be possible to observe that the FortiGate replies the TLSv1 with 'Alert' in 'Info' column on SSL handshakes as shown in the screenshot below: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.