2.1.10 Ensure management GUI listens on secure TLS version

Information

As we move towards better encryption capabilities, we need to also ensure GUI access is properly secured. TLS 1.3 is currently the most secure SSL/TLS supported version for SSL-encrypted administrator access (at this time of writing).

Use higher version of SSL/TLS to prevent MiTM attacks.

Solution

CLI:

config system global
set admin-https-ssl-versions tlsv1-3

See Also

https://workbench.cisecurity.org/benchmarks/15284

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-18

Plugin: FortiGate

Control ID: 02ec54dbf5581d5a01f2021a3d5396bd3a5ad07b3046a1d29b4e6534d77b3177