Description | This article provides steps to disable DTLS 1.0 on FortiGate and enforce DTLS 1.2 for SSL VPN connections. Disabling DTLS 1.0 helps mitigate security risks and ensures compliance with modern encryption standards. |
Scope | FortiGate. |
Solution |
To disable DTLS 1.0 and enforce DTLS 1.2 for SSL VPN, configure: config vpn ssl settings set dtls-tunnel enable set dtls-min-proto-ver dtls1-2 end
This ensures DTLS 1.0 is disabled, and only DTLS 1.2 is allowed.
Related article: Technical Tip: Using DTLS to improve SSL VPN performance |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.