Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
amorales
New Contributor

Blocking TLS 1.1 in firewall rules

I am wondering if there is an option to block tls 1.1 traffic in firewall rules without having to enable the ssl offloading. In checkpoint it is possible to do it with IPS but I cannot find any signature to block this. Maybe crafting my own signature? Has anyone been able to achieve this? Thanks!
3 REPLIES 3
Markus
Valued Contributor

Yes, you can do this with app control. Create a profile, set the categories as for your environment (maybe you have already one in place) In the override section, add the unwanted ssl/tls versions and set them to block. Best


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
amorales

Thank you very much Markus. Concerning app control, I suppose that in this particular case full ssl inspection is not needed right? I suppose that not but just for confirmation.
Markus
Valued Contributor

Hi Arnaldo Yes, you're right. SSL deep inspection is not needed for the hole network service category. Only Cloud Applications require deep inspection. Best


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
Labels
Top Kudoed Authors