Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ncrealteit
New Contributor

Send logs to FortiAnalyzer - disable SSL encryption not possible in 6.0.4?

We are using Fortigates on sattelite connection and in order to optimize then are we using built in WAN optimization. In order to wan optimize FortiAnalyzer traffic then is source interface set to LAN IP on the fortigate and SSL encryption would be nice to remove in order to optimze.

 

I have not been able to disable encryption in 6.0.4. In GUI if trying to disable it is on again after loading setting and in cli (enc-algorithm)  is it only possible to select between high-medium, high and low - it is not possible to disable. 

 

Do anyone have information that could help me solving this issue? 

2 REPLIES 2
chall_FTNT
Staff
Staff

Per Mantis 491465, starting in FortiOS 6.0.3, the ability to disable SSL for OFTP has been disabled for vulnerability reasons.  If you need to send logs without encryption, disable the reliable option which causes logs to be sent via UDP instead.

Chris Hall
Fortinet Technical Support
ncrealteit

Hi Per Thank you for the clarification, but using UDP would not make the traffic possible to wan opt through the Fortigate :o(
Labels
Top Kudoed Authors