Description |
This article describes the solution for the failure of PCI scan for SSL VPN using Tlsv1.2 |
Scope | FortiGate |
Solution |
In some cases, a PCI scan could result in failure as an insecure cipher is used in Tlsv1.2 for SSL VPN. Below is an example from a PCI scan.
On the admin GUI, it is possible to disable ssl-static-key-ciphers and use strong-crypto to eliminate this issue. However, those options are not available for an SSL VPN setting. To work around this, ban insecure ciphers using the following commands:
set banned-cipher RSA DHE CAMELLIA 3DES SHA1 SHA256 SHA384 AESCCM end
After that, running the scan again will show the connection is only established using strong ciphers:
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.