FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
chefedinga
Staff
Staff
Article Id 354631
Description This article describes a possible troubleshooting action for ECH errors.
Scope FortiOS.
Solution

If the website cannot be accessed because the browser gives the error 'ERR_ECH_NOT_NEGOTIATED'.

 

Possible solutions to workaround this issue is to:

  1. Check if the policy is in flow mode inspection. If necessary, change to the proxy-based inspection mode.
  2. In v7.4.4+: by default, certificate inspection is set to 'Block'. Try selecting the Encrypted Client Hello to 'Allow'.

 

ECH_Allow_Block.PNG

 

  1. If Deep Packet Inspection is used, check if the 'ClientHello' packet is encrypted (verify this in a Wireshark capture). Try exempting the website using ECH. One example is exempting cloud-flare-ech.com.
  2. Check if the browser is using ECH: https://public.tls-ech.dev/. If ECH is being used, try using different DNS servers and disable DNS over HTTPS.
  • On FireFox, navigate to Privacy & Security -> Enable DNS over HTTPS Using -> Off.
  • On Chrome, disable the TLS 1.3 Early Data under 'chrome://flags/'.

Note:

 

If the issue persists, open a TAC ticket providing all of the necessary logs for analysis.