FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Umer221
Staff
Staff
Article Id 280833
Description This article describes how to mitigate the 'TLS.ROBOT.Attack' Vulnerability on FortiGate in order to pass a PCI scan by adjusting the RSA algorithm settings for SSL VPN.
Scope FortiOS, FortiGate, SSL VPN.
Solution To get detailed understanding of the 'TLS.ROBOT.Attack' Vulnerability on FortiGate, see the FortiGuard encyclopedia article.

Weak cipher suites need to be replaced with stronger cipher suites in order to mitigate this vulnerability. Before making any changes, make sure to have the latest backup and then enter the following commands in the FortiGate CLI:

 

config vpn ssl settings

set ciphersuite TLS-AES-256-GCM-SHA384

end

 

SSL 1.jpg

 

Note: Multiple algorithms can be selected for this configuration, as shown in the picture below:

SSL 2.jpg

 

Run a scan again after updating the cipher suites.

Contributors