2.1.10 Ensure management GUI listens on secure TLS version

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

As we move towards better encryption capabilities, we need to also ensure GUI access is properly secured. TLS 1.3 is currently the most secure SSL/TLS supported version for SSL-encrypted administrator access (at this time of writing).

Rationale:

Use higher version of SSL/TLS to prevent MiTM attacks.

Solution

CLI:

config system global
set admin-https-ssl-versions tlsv1-3

Default Value:

FortiOS 7.x - TLS 1.2 and 1.3 enabled

FortiOS 6.x - TLS 1.1, 1.2, and 1.3 enabled

See Also

https://workbench.cisecurity.org/benchmarks/12961