Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kayescomputers
New Contributor

How to disable TLS V1.0

Hi There, With strong-crypto enabled, I see that TLS V1.0 is still enabled and I am failing PCI compliance scans because of this. Is there any way to manually disable TLS V1.0 through the CLI?  Currently running V5.2 build 436 on Fortimail 60D.

 

Cheers - MT

7 REPLIES 7
emnoc
Esteemed Contributor III

Simple

 

 

The cfg mode cli and set the TLS version(s) that you want under 

 

config system global

 

Ken

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
kayescomputers

Ok, I must be doing something fundamentally wrong then?  I assume the command would be 'set tls1_0 disable' ?? 

 

<edit>  screenshot shows hyphen, I did try with underscore as well and got the same error. 

 

Cheers - MT

emnoc
Esteemed Contributor III

No opposite just set the levels you want ?

 

Here's a blog btw ;

 

http://socpuppet.blogspot...version-fortimail.html

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
kayescomputers

Seems I have this talent for making what should be simple rather difficult.... LOL

 

Please see screenshot.

 

Cheers - MT

kayescomputers

Got it Ken, had to upgrade to 5.2.5

 

Thanks for your help again!

 

Cheers - MT

emnoc
Esteemed Contributor III

had to upgrade to 5.2.5

 

That snapshot was done a racked  model  running (5.1.6 GA). I'm surprise you had to upgrade.  I'm glad it worked out for you.

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Alexis_G

See:

https://fortiguard.com/psirt/FG-IR-14-031

 

--------------------------------------------

If all else fails, use the force !

-------------------------------------------- If all else fails, use the force !
Labels
Top Kudoed Authors