Description |
This article describes how to handle an issue where using Diffie-Hellman (DH) parameters as 2048 does not fix a vulnerability. |
Scope |
FortiGate OS. |
Solution |
Background:
Check the DH parameters under the global configuration:
Conclusion: Increasing DH Parameters to 8192 Bits not only fixes the issue, but impacts the FortiGate firewall in the following ways:
|