Supported cipher suites for endpoint management
For data at rest, FortiSASE relies on the storage layer of its cloud platform for encryption, namely, all disk volumes are encrypted.
For FortiSASE endpoint management using FortiClient Cloud, encryption in transit protects the following traffic:
-
FortiClient Telemetry traffic to TCP port 8013 on FortiClient Cloud uses a proprietary text-based protocol on top of TLS.
-
FortiGate traffic to TCP port 443 on FortiClient Cloud uses a proprietary REST API on top of TLS.
The following tables list the supported TLS 1.3 and TLS 1.2 cipher suites for the above encrypted traffic.
FortiClient Telemetry to FortiClient Cloud traffic
| TLS 1.3 cipher |
|---|
| TLS_AES_128_GCM_SHA256 |
| TLS_AES_256_GCM_SHA384 |
| TLS_CHACHA20_POLY1305_SHA256 |
| TLS 1.2 cipher |
|---|
|
ECDHE-RSA-AES256-GCM-SHA384 |
| ECDHE-RSA-CHACHA20-POLY1305 |
| ECDHE-ARIA256-GCM-SHA384 |
| ECDHE-RSA-AES128-GCM-SHA256 |
| ECDHE-ARIA128-GCM-SHA256 |
| ECDHE-RSA-AES256-SHA384 |
| ECDHE-RSA-CAMELLIA256-SHA384 |
| ECDHE-RSA-AES128-SHA256 |
| ECDHE-RSA-CAMELLIA128-SHA256 |
| ECDHE-RSA-AES256-SHA |
| ECDHE-RSA-AES128-SHA |
FortiGate to FortiClient Cloud REST API traffic
| TLS 1.3 cipher |
|---|
| TLS_AES_256_GCM_SHA384 |
| TLS_CHACHA20_POLY1305_SHA256 |
| TLS_AES_128_GCM_SHA256 |
| TLS 1.2 cipher |
|---|
| ECDHE-RSA-AES256-GCM-SHA384 |
| ECDHE-RSA-AES128-GCM-SHA256 |
| DHE-RSA-AES256-GCM-SHA384 |
| DHE-RSA-AES128-GCM-SHA256 |
| ECDHE-RSA-AES256-SHA384 |
| ECDHE-RSA-AES256-SHA |
| DHE-RSA-AES256-CCM8 |
| DHE-RSA-AES256-CCM |
| DHE-RSA-AES256-SHA256 |
| DHE-RSA-AES256-SHA |
| ECDHE-RSA-AES128-SHA256 |
| ECDHE-RSA-AES128-SHA |
| DHE-RSA-AES128-CCM8 |
| DHE-RSA-AES128-CCM |
| DHE-RSA-AES128-SHA256 |
| DHE-RSA-AES128-SHA |
| AES256-GCM-SHA384 |
| AES128-GCM-SHA256 |
| AES256-CCM8 |
| AES256-CCM |
| AES128-CCM8 |
| AES128-CCM |
| AES256-SHA256 |
| AES128-SHA256 |
| AES256-SHA |
| AES128-SHA |