FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dbabic
Staff
Staff
Article Id 198122

Description
This articles explains how the HSTS parameter max age for SSL VPN portal is not configurable in FortiGate, regardless of the firmware, and the available options are as follows.
Solution
Since FortiOS 5.4.8 and FortiOS 5.6.4 HSTS support is added and enforced. (469037)

Then, max-age value was increased to one year starting with FortiOS 5.4.10, 5.6.5 and 6.0.1 (472195) to match certain security standard ratings.

Since the existing RFCs are not stating how long this "long time" should be, a longer time is considered to be better. The max-age parameter is not user-configurable in any of the FortiOS versions to date.

The available choices are:

- 1year for the firmware versions above (or newer)
- 6months for older versions of each branch of firmware.


 

Contributors