| Description | This article describes how to mitigate the 'TLS.ROBOT.Attack' Vulnerability on FortiGate in order to pass a PCI scan by adjusting the RSA algorithm settings for SSL VPN. |
| Scope | FortiOS, FortiGate, SSL VPN. |
| Solution | To get detailed understanding of the 'TLS.ROBOT.Attack' Vulnerability on FortiGate, see the FortiGuard encyclopedia article. Weak cipher suites need to be replaced with stronger cipher suites in order to mitigate this vulnerability. Before making any changes, make sure to have the latest backup and then enter the following commands in the FortiGate CLI:
config vpn ssl settings set ciphersuite TLS-AES-256-GCM-SHA384 end
Note: Multiple algorithms can be selected for this configuration, as shown in the picture below:
Run a scan again after updating the cipher suites. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.