Description |
This article describes why SSL VPN stops working after upgrading from v7.0.x to v7.2.x in the FortiGate-1500D model. The SSL VPN debugs show 'no shared cipher' and the browser displays 'SSL_ERROR_NO_CYPHER_OVERLAP':
|
Scope | FortiGate-1500D |
Solution |
From the config file, under SSL VPN settings, the server cert is 'Fortinet_Factory'.
GortiGate-1500D is a CP8 platform and the 'Fortinet_Factory' is 1024-bit.
FortiOS was upgraded to OPENSSL 3.0.2 since v7.2.1 0752141, the 'Fortinet_Factory' does not fit OPENSSL 3.0 requirement, which causes the SSL handshake to fail.
Debugs:
FortiGate-1500D # 2022-12-02 13:22:58 [357:root:2]allocSSLConn:306 sconn 0x7f8ba56b1800 (0:root)
Creating an SSL VPN cert on FortiGate will resolve the issue:
config vpn ssl settings end
To create a certificate, Go to VPN -> SSL VPN Settings -> Server Certificate -> Create Certificate -> Generate Certificate.
Once generated, replace the old SSL VPN certificate with the new one. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.