6.1.2 Enable Limited TLS Versions for SSL VPN

Information

Enable and disable TLS versions and Cipher suites for more granular control of SSL VPN connections and enforcing more secure connections.

Limiting TLS versions to more secure versions as well as enforcing stronger ciphers increases the security of the SSL VPN connections.

Solution

CLI:

config vpn ssl settings
set ssl-max-proto-ver tls1-3
set ssl-min-proto-ver tls1-2
set algorithm high

See Also

https://workbench.cisecurity.org/benchmarks/24708

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17, 800-53|AC-17(1), 800-53|AC-17(3)

Plugin: FortiGate

Control ID: 6af40a86d042b9dec57aed8a7b1fb43dcbe4c70e53c7debb177d58132e8c5bd8