Skip to main content
MikePruett
New Member
February 15, 2015
Question

Fortigate Vulnerability Scan Makes Samsung Printer Print Jibberish

  • February 15, 2015
  • 12 replies
  • 18000 views

Not sure if this is the right area but I figured since it is the Vulnerability scan that is built into the Fortigate I might as well post it. Scheduled some weekly vulnerability scans on my home network using the integrated vulnerability scanner on the Fortigate.

 

Well, I was in the restroom just now (12:30 at night my time) and I heard a printer kick off...I didn't know it was my printer at first so I ran in there ready to go toe to toe with an intruder.

 

Saw it was the printer and took a look. My Samsung printer was printing out random jibberish pages and one of them said "Rand-Test-User-Fortinet" a bunch of jibberish and then Squelda

 

After some digging into the firewall I realized it was running a scan.

 

I then remember that my main office experienced the same thing last week when the scan was going off at HQ (HQ also uses a Samsung printer). Needless to say, don't freak out if you run a Samsung style printer and your fortigate vulnerability scans your network and causes it to print some jibberish etc. You will be wasting paper but don't be alarmed haha.

    12 replies

    jb_kalm
    New Member
    February 17, 2015

    Interesting. Thanks for the heads up Mike! 

     

    Thanks,

     

    jb

    Shawn_W
    New Member
    February 17, 2015

    Interesting.  Has anyone else experienced similar issues?  I will keep a heads up for this.  Thanks.

    MikePruett
    New Member
    February 18, 2015

    Just a heads up but I tested at another client's office. Does it to HP printers too haha

    picsas
    New Member
    March 10, 2015

    Our Kyocera printers (different models) print the same thing.

     

    But vulnerability scan is turned off on our Fortigate..

    infolog
    New Member
    April 20, 2015

    Good afternoon,

    same problem with Lexmark printers and vulnerability scan off.. Have you find any solutions?

    In our case, prints start at 0:00 and often trigger the alarm in the office 

     

    many thanks in advance for your reply

     

    Mirco Palandri

    picsas
    New Member
    April 20, 2015

    No solution for me yet.. Updated to the latest Firmware but didn't change anything.

    It only happens on the internal Network where the fortigate is located too, routed subnets are not affected

    infolog
    New Member
    April 27, 2015

    Hi,

    in firmware 5.2.3 i found the solution.

    We notice that if you disable the vulnerability scan feature, the scan remains enabled.

    to definitively disable it, from console use device-netscan command:

    config system interface

            edit "internal interface"

                  set device-netscan disable

            end

    end

     

    AlexFeren
    New Member
    May 31, 2016

    > We notice that if you disable the vulnerability scan feature

     

    I don't believe it's possible to disable this feature (setting system global's 'gui-vulnerability-scan' to "disable" only removes "Vunerability Scan" menu from the GUI).

     

    This is what I observe: Vulnerability Scan of 'assets' (see "config netscan assets") is initiated in any of these 3 ways:

    1. on-demand (ie. manually), using "execute netscan start scan";

    2. per schedule (see "config netscan settings") IF asset's 'scheduled' is "enable";

    3. per schedule (see "config netscan settings") IF an asset's address is within the subnet of the interface whose interface (see "config system interface") has both 'device-identification' and 'device-netscan' set to "enable".

     

    So, to practically disable the scanning, either: (i) remove all assets whose address is within the interface's subnet (with netscan) or (ii) disable netscan on the interface whose subnet contains assets' address.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.