FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kumarh
Staff
Staff
Article Id 278926
Description This article describes how to use FortiGate to mitigate the ROBOT vulnerability found on TLSv1.2 using AES256-SHA with a weak oracle.
Scope All FortiGate Firmware
Solution

This vulnerability exploits ciphers. To prevent the vulnerability being used, disable ciphers in the CLI.

 

Before making any changes, make sure to have the latest backup and then enter the following commands in the FortiGate CLI:

 

config vpn ssl settings

set banned-cipher CAMELLIA

end

 

Run a scan again after blocking the CAMELLIA cipher suites.

Contributors