Current Limitation Observed
In FortiWeb 7.4.11 deployment operating in reverse proxy mode, TLS protocol and cipher suite configuration appears to be global across all protected applications.
Operational Challenge
Our goal is to enforce strong TLS protocols and cipher suites on a per-application basis, following a phased rollout approach:
However, because TLS cipher and protocol enforcement is global, any change immediately impacts all applications protected by FortiWeb. This prevents us from safely testing TLS hardening on a single application before expanding enforcement.
This is especially challenging in environments where:
Clarification Request
Is there any supported way in FortiWeb to:
Enforce TLS protocols and cipher suites per application in reverse proxy mode?
If this capability does not exist today:
Why This Capability Is Important
Hi Saif
It can be configured per policy.
In the related server policy just click "Advanced SSL settings" then set it as needed.
| User | Count |
|---|---|
| 2882 | |
| 1446 | |
| 843 | |
| 822 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.