FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
AndrewX
Staff
Staff
Article Id 372755
Description

This article describes how to handle an issue where using Diffie-Hellman (DH) parameters as 2048 does not fix a vulnerability.

Scope

FortiGate OS.

Solution

Background:

  • Upon setting up 2048 DH parameters, the following alert information is still received about a vulnerability:


11.png

 

Check the DH parameters under the global configuration:

 

22.png

 

Conclusion:

Increasing DH Parameters to 8192 Bits not only fixes the issue, but impacts the FortiGate firewall in the following ways:

  1. Enhanced Security:
  • Increased computational complexity: Larger DH parameters require significantly more computational power to break, making it much harder for attackers to compromise the security of the VPN.
  • Resistance to future attacks: As computing power grows, increasing the key size helps future-proof security infrastructure.
  1. Potential Performance Impact:
  • Increased CPU usage: Larger DH parameters can lead to slightly increased CPU usage during the key exchange process. However, modern hardware can typically handle this overhead without significant performance degradation.
  • Increased network traffic: The larger key exchange messages may result in slightly increased network traffic.
Contributors