6.1.2 Enable Limited TLS Versions for SSL VPN

Information

Enable and disable TLS versions and Cipher suites for more granular control of SSL VPN connections and enforcing more secure connections.

Limiting TLS versions to more secure versions as well as enforcing stronger ciphers increases the security of the SSL VPN connections.

Solution

CLI:

config vpn ssl settings
set ssl-max-prot-ver tls1-3
set ssl-min-proto ver tls1-2
set algorithm high

See Also

https://workbench.cisecurity.org/benchmarks/15284

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: FortiGate

Control ID: c09aa6610e63e7eb8a904ad57a1d8c68254c20aebabe27d77bfbe2ae3af07e72