Skip to main content
WEER
New Member
January 7, 2015
Solved

Poodle attack

  • January 7, 2015
  • 5 replies
  • 6304 views

Dear All,

I have fortigate 800c(version 5.00556) and IPS signature has expired and in the process of renewing.

There is a poodle vulnerability and it will solve with 5.587..

My question is ..1)is it possible to update without renewing?

                        2)from where can I download this 5.587 ?

                        3)if it is not possible to download wihout renewing..can we get temporally signature till it get renewed?

 

Thanks 

 

    Best answer by ede_pfau

    hi,

     

    without a valid subscription the FGT will not update automatically.

    You may try to download the signature file manually. Go to fortinet.com, Service&Support, and log in to your account. Then Downloads, Fortiguard updates. Select the FortiOS version which is running and download the 'nids' file.

    In the WebGUI of the FGT, go to Config, Fortiguard, find the IPS section and update manually.

     

    All this depends on whether your account will still be granting you access.

     

    Aside from this, contract renewals often take only 1-2 days from order to execution. I have even experienced putting in an order at 3 pm and getting the renewal registered by 5 pm on the same day.

    5 replies

    Christopher_McMullan
    Staff
    Staff
    January 7, 2015

    I won't post the signature here, since (as far as I know) it hasn't been made public as a separate item. However, you can open a TAC ticket to request it for yourself.

     

    You cannot update without a valid license, so to receive the signature automatically, you would have to wait for the renewal process to finish.

     

    The FortiGuard Advisory on the POODLE vulnerability (http://www.fortiguard.com/advisory/CVE-2014-8730--Poodle-for-TLS--vulnerability/) does also mention another possibility as a workaround: disabling hardware acceleration. The attack will not proceed when the traffic is directed through the CPU instead. Please see the advisory for more details.

    ede_pfau
    SuperUser
    ede_pfauAnswer
    SuperUser
    January 7, 2015

    hi,

     

    without a valid subscription the FGT will not update automatically.

    You may try to download the signature file manually. Go to fortinet.com, Service&Support, and log in to your account. Then Downloads, Fortiguard updates. Select the FortiOS version which is running and download the 'nids' file.

    In the WebGUI of the FGT, go to Config, Fortiguard, find the IPS section and update manually.

     

    All this depends on whether your account will still be granting you access.

     

    Aside from this, contract renewals often take only 1-2 days from order to execution. I have even experienced putting in an order at 3 pm and getting the renewal registered by 5 pm on the same day.

    WEER
    WEERAuthor
    New Member
    January 8, 2015

     

    Hi Ede,

    I will try this..Since this is an update of IPS ,hope I can do this during working hours without any down time?

    Thanks a lot

     

    WEER
    WEERAuthor
    New Member
    January 8, 2015

    dear Ede,

    Can you tell whether I need a downtime for this update?Need any restart after the update??

     

    Waiting for your response

    ede_pfau
    SuperUser
    SuperUser
    January 8, 2015

    hi,

     

    and sorry, I was asleep at night :) (CET here)

     

    Absolutely, the update does not require any downtime. CPU load might peak but that doesn't matter.

    While you're at it, update the AV signatures as well.