We are encountering an issue with FPX where the Palo Alto firewall attempts to retrieve updates via FPX, but the connection is randomly refused.
Upon analyzing the packet capture from FPX during the issue, we observed that FPX uses TLS 1.0 to communicate with the Palo Alto update server, causing the connection to fail. However, when FPX uses TLS 1.2, the connection is successful.
Is there any option to enforce FPX to use TLS 1.2 for communication with the Palo Alto update server in a specific policy or profile?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Please note that this request will be sent to Fortinet Global Community platform to draw more visibility.
If this has already been solved, can you please mark it as "Solved"
Please contact your local EPSP PM for any concern
Thank you
Joanne
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.