Fortinet white logo
Fortinet white logo

Supported cipher suites for endpoint management

Supported cipher suites for endpoint management

For data at rest, FortiSASE relies on the storage layer of its cloud platform for encryption, namely, all disk volumes are encrypted.

For FortiSASE endpoint management using FortiClient Cloud, encryption in transit protects the following traffic:

  • FortiClient Telemetry traffic to TCP port 8013 on FortiClient Cloud uses a proprietary text-based protocol on top of TLS.

  • FortiGate traffic to TCP port 443 on FortiClient Cloud uses a proprietary REST API on top of TLS.

The following tables list the supported TLS 1.3 and TLS 1.2 cipher suites for the above encrypted traffic.

FortiClient Telemetry to FortiClient Cloud traffic

TLS 1.3 cipher
TLS_AES_128_GCM_SHA256
TLS_AES_256_GCM_SHA384
TLS_CHACHA20_POLY1305_SHA256
TLS 1.2 cipher

ECDHE-RSA-AES256-GCM-SHA384

ECDHE-RSA-CHACHA20-POLY1305
ECDHE-ARIA256-GCM-SHA384
ECDHE-RSA-AES128-GCM-SHA256
ECDHE-ARIA128-GCM-SHA256
ECDHE-RSA-AES256-SHA384
ECDHE-RSA-CAMELLIA256-SHA384
ECDHE-RSA-AES128-SHA256
ECDHE-RSA-CAMELLIA128-SHA256
ECDHE-RSA-AES256-SHA
ECDHE-RSA-AES128-SHA

FortiGate to FortiClient Cloud REST API traffic

TLS 1.3 cipher
TLS_AES_256_GCM_SHA384
TLS_CHACHA20_POLY1305_SHA256
TLS_AES_128_GCM_SHA256
TLS 1.2 cipher
ECDHE-RSA-AES256-GCM-SHA384
ECDHE-RSA-AES128-GCM-SHA256
DHE-RSA-AES256-GCM-SHA384
DHE-RSA-AES128-GCM-SHA256
ECDHE-RSA-AES256-SHA384
ECDHE-RSA-AES256-SHA
DHE-RSA-AES256-CCM8
DHE-RSA-AES256-CCM
DHE-RSA-AES256-SHA256
DHE-RSA-AES256-SHA
ECDHE-RSA-AES128-SHA256
ECDHE-RSA-AES128-SHA
DHE-RSA-AES128-CCM8
DHE-RSA-AES128-CCM
DHE-RSA-AES128-SHA256
DHE-RSA-AES128-SHA
AES256-GCM-SHA384
AES128-GCM-SHA256
AES256-CCM8
AES256-CCM
AES128-CCM8
AES128-CCM
AES256-SHA256
AES128-SHA256
AES256-SHA
AES128-SHA

Supported cipher suites for endpoint management

Supported cipher suites for endpoint management

For data at rest, FortiSASE relies on the storage layer of its cloud platform for encryption, namely, all disk volumes are encrypted.

For FortiSASE endpoint management using FortiClient Cloud, encryption in transit protects the following traffic:

  • FortiClient Telemetry traffic to TCP port 8013 on FortiClient Cloud uses a proprietary text-based protocol on top of TLS.

  • FortiGate traffic to TCP port 443 on FortiClient Cloud uses a proprietary REST API on top of TLS.

The following tables list the supported TLS 1.3 and TLS 1.2 cipher suites for the above encrypted traffic.

FortiClient Telemetry to FortiClient Cloud traffic

TLS 1.3 cipher
TLS_AES_128_GCM_SHA256
TLS_AES_256_GCM_SHA384
TLS_CHACHA20_POLY1305_SHA256
TLS 1.2 cipher

ECDHE-RSA-AES256-GCM-SHA384

ECDHE-RSA-CHACHA20-POLY1305
ECDHE-ARIA256-GCM-SHA384
ECDHE-RSA-AES128-GCM-SHA256
ECDHE-ARIA128-GCM-SHA256
ECDHE-RSA-AES256-SHA384
ECDHE-RSA-CAMELLIA256-SHA384
ECDHE-RSA-AES128-SHA256
ECDHE-RSA-CAMELLIA128-SHA256
ECDHE-RSA-AES256-SHA
ECDHE-RSA-AES128-SHA

FortiGate to FortiClient Cloud REST API traffic

TLS 1.3 cipher
TLS_AES_256_GCM_SHA384
TLS_CHACHA20_POLY1305_SHA256
TLS_AES_128_GCM_SHA256
TLS 1.2 cipher
ECDHE-RSA-AES256-GCM-SHA384
ECDHE-RSA-AES128-GCM-SHA256
DHE-RSA-AES256-GCM-SHA384
DHE-RSA-AES128-GCM-SHA256
ECDHE-RSA-AES256-SHA384
ECDHE-RSA-AES256-SHA
DHE-RSA-AES256-CCM8
DHE-RSA-AES256-CCM
DHE-RSA-AES256-SHA256
DHE-RSA-AES256-SHA
ECDHE-RSA-AES128-SHA256
ECDHE-RSA-AES128-SHA
DHE-RSA-AES128-CCM8
DHE-RSA-AES128-CCM
DHE-RSA-AES128-SHA256
DHE-RSA-AES128-SHA
AES256-GCM-SHA384
AES128-GCM-SHA256
AES256-CCM8
AES256-CCM
AES128-CCM8
AES128-CCM
AES256-SHA256
AES128-SHA256
AES256-SHA
AES128-SHA