2.1.10 Ensure management GUI listens on secure TLS version

Information

As we move towards better encryption capabilities, we need to also ensure GUI access is properly secured. TLS 1.3 is currently the most secure SSL/TLS supported version for SSL-encrypted administrator access (at this time of writing).

Rationale:

Use higher version of SSL/TLS to prevent MiTM attacks.

Solution

CLI:

config system global
set admin-https-ssl-versions tlsv1-3

Default Value:

FortiOS 7.x - TLS 1.2 and 1.3 enabled

FortiOS 6.x - TLS 1.1, 1.2, and 1.3 enabled

See Also

https://workbench.cisecurity.org/benchmarks/12961

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-18, 800-53|AC-18(1), 800-53|AC-18(3), 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SC-23, CSCv7|5.1

Plugin: FortiGate

Control ID: 89990a39736bc50af2e54c0a8cc56350cba6ff337f2212596a3ecbd71e17600c