Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
yfourar
New Contributor

SSL alert sent

Hello, after I upgraded my FortiOS version to 6.0.12 I receive these alerts in eventlogging

Message meets Alert condition date=2021-06-07 time=17:49:59 devname=rinxcomfw1 devid=FGT60XXXXXX logid="0105048039" type="event" subtype="wad" level="error" vd="root" eventtime=1623080999 logdesc="SSL fatal alert sent" session_id=242277 policyid=1 srcip=X.X.X.X srcport=X dstip=X.X.X.X dstport=443 action="send" alert="2" desc="illegal parameter" msg="SSL Alert sent" Message meets Alert condition date=2021-06-07 time=17:49:59 devname=rinxcomfw1 devid=FGT60DXXXXXX logid="0105048003" type="event" subtype="wad" level="error" vd="root" eventtime=1623080999 logdesc="SSL handshake length invalid" session_id=242277 policyid=1 srcip=X.X.X.X srcport=X dstip=X.X.X.X dstport=443 action="close" handshake="ClientHello" msg="Bad length in SSL hands

The policy ID 1 is the internet access & I use cetificate inspection.

Anyone seeing the same thing or knowns what kind of traffic is causing these alerts?

2 REPLIES 2
tzepf
New Contributor

Any news on this? Same behaviour with me after Upgrading to 6.4.7 - i use SD WAN with Volume based load balancing and SSL Inspection...

 

Is this a concern or can i ignore those?

Tedkaznj
New Contributor

Did you check if these are users using browser with broken TLS?

Labels
Top Kudoed Authors