Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jeff363
Visitor

PCI Non Compliance HTTP/1.0 Protocol Downgrade Detected

How do I Configure server to reject HTTP/1.0 requests with "505 HTTP Version Not Supported" status and enforce minimum HTTP/1.1 protocol version?  I am using Fortigate 60f and I need to make necessary changes so that my Merchant Service PCI Compliance passes.  This is the last setup that I need and would like to make the fix with GUI, not CLI.  Any help would be great appreciated.

1 REPLY 1
Toshi_Esumi
SuperUser
SuperUser

One of our customers reported the same pentest failed report due to the same "HTTP/1.0" issue (the report says HTTP/1.1 is still unacceptable, while only HTTP/2 and /3 are acceptable) against their VDOM serving SSL VPN with 7.2.12. Since I couldn't find a good way to "silence" this, we opened a TAC case 10 days ago. TAC's initial response was:
"The reported behavior has been escalated to our PSIRT team, and we are currently awaiting a status update. Any feedback received from then will be shared through this ticket."
And, we still haven't gotten any update from them yet. Since they didn't come back and say "you have to upgrade to 7.4.x or 7.6.x", I'm assuming upgrading it to a newer generation wouldn't resolve this issue. 

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors