Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
amorales
New Contributor II

Blocking TLS 1.1 in firewall rules

I am wondering if there is an option to block tls 1.1 traffic in firewall rules without having to enable the ssl offloading. In checkpoint it is possible to do it with IPS but I cannot find any signature to block this. Maybe crafting my own signature? Has anyone been able to achieve this? Thanks!
3 REPLIES 3
Markus
Valued Contributor

Yes, you can do this with app control. Create a profile, set the categories as for your environment (maybe you have already one in place) In the override section, add the unwanted ssl/tls versions and set them to block. Best


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
amorales
New Contributor II

Thank you very much Markus. Concerning app control, I suppose that in this particular case full ssl inspection is not needed right? I suppose that not but just for confirmation.
Markus
Valued Contributor

Hi Arnaldo Yes, you're right. SSL deep inspection is not needed for the hole network service category. Only Cloud Applications require deep inspection. Best


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors