FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
sthapa
Staff
Staff
Article Id 197803
Description
This article describes about how to block lower TLS version for pass-through traffic.

Solution
It is possible to block lower TLS version TLS 1.0 & 1.1 version for pass-through traffic using application control profile.

- Enabling application profile.
- Select application Overrides signature by selecting '+ Create New'.





- Then, Select 'SSL_TLSv1.0 and SSL_TLSv1.1' signature select 'Ok' and set action as 'Block'.




- Use this application profile in the IPv4 policy to block TLS 1.0 & 1.1 Version traffic.




Go to Log & report -> Application Control -> Check Logs.

Contributors