Reports started rolling in on Monday, 22 April 2024, at approximately 07:00 AWST (Sunday, 21 April 2024, 23:00 UTC) that people could not access HTTPS websites but could access HTTP websites.
We found that the common denominator was that only customers with a PPPoE dialler for the WAN/Internet service were impacted.
We've seen this in the past and resolved it by adding "set tcp-mss 1452" to the LAN/INSIDE interface/s configuration of our Fortigates.
We provide Internet to many of the customers, but not all - it does not seem to be isolated to a specific network or ISP.
I wasn't involved in the initial information gathering, so I'm unsure if it was limited to specific sites, but I was aware that sites such as office.com (all of Microsoft), www.bom.gov.au, and www.news.com.au were impacted.
The question is, why is it only impacting Fortigates (we have customers with different firewall vendors who didn't have the same issue), & why were they working fine before when the reports came in?
We had done no firmware updates to any of the units, nothing was changed from our side.
Most (if not all) units have automatic Fortiguard updates.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Looks like this has happened due to a default setting change in Chrome (and Edge is a derivative of Chrome) changing “TLS 1.3 Hybridized Kyber Support” from disabled to enabled which apparently adds extra data in the client hello message:
https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/
Chrome 124 was released April 16th (not all machines would have immediately pulled down the update) so this lines up with the timeline of when issues have cropped up at various customer sites sites. Lowering TCP MSS has worked around this issue by allowing packets with extra data in them to go through without packet defragmentation happening. There are many threads recently about this:
https://www.reddit.com/r/chrome/comments/1c8ucus/problems_with_chrome_and_cloudflare/
https://www.reddit.com/r/chrome/comments/1c83js4/firewall_issues_after_latest_update/
https://www.reddit.com/r/sonicwall/comments/1cac4ii/content_filter_blocking_cfs_legitimate_traffic/ (Sonic Wall)
https://www.reddit.com/r/sysadmin/comments/1ca1chq/hello_im_new_to_both_this_subreddit_and_a/
It (TLS 1.3 Hybridized Kyber support) has been known for a while as an issue with Fortigates but only now has the defaults changed in Chrome: https://community.fortinet.com/t5/Support-Forum/SSL-Deep-Inspection-Google-Chrome/td-p/286352/page/2
With regards to Edge: "Also downgrading to 123.X.X versions works" according to: https://www.reddit.com/r/sonicwall/comments/1cac4ii/content_filter_blocking_cfs_legitimate_traffic/.
Edge 124 was released 18-Apr-2024.
Exactly same issue around here, thank you for posting and making the problem more visible. Might help people in the same situation.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1696 | |
1092 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.