Description |
This article describes how to prevent information disclosure through SSL-VPN URL:
https://<Remote_Gateway_IP:Port_Number>/remote/fgt_lang?lang=en |
Scope | FortiGate |
Solution |
The SSL-VPN URL:
https://<Remote_Gateway_IP:Port_Number>/remote/fgt_lang?lang=en
points to a language file but it is not considered as security concern or sensitive information on the device.
It is possible to try blocking the page using Web Application Firewall(WAF) policy but sslvpn login page would not display properly.
The language file Page while accessing SSL-VPN URL:
https://<Remote_Gateway_IP:Port_Number>/remote/fgt_lang?lang=en:
var fgt_lang = |