Fortigate - VPN SSL cipher suite > than 128 bits

Information

Ensure VPN SSL settings use a cipher suite that is greater than 128 bits.

Solution

Issue the following command to use a cipher suite that is greater than 128 bits for VPN SSL:

config vpn ssl settings
set algorithm high
end

See Also

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/612504/hardening-your-fortigate

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2)

Plugin: FortiGate

Control ID: 97ca817d829651366bf6a6ca14cf05d13a66336845a35989a197ac20bade15fd