| Description | This article describes step-by-step instructions on how to disable CBC (Cipher Block Chaining) ciphers on a FortiSIEM virtual appliance in order to enhance security. |
| Scope | FortiSIEM. |
| Solution |
Cipher Block Chaining (CBC) is a mode of operation for block ciphers that may be vulnerable to certain security risks, such as padding oracle attacks. To enhance the security of the FortiSIEM virtual appliance, disable CBC ciphers and configure more secure encryption options.
Disabling CBC Ciphers on FortiSIEM Virtual Appliance:
sudo nano /etc/ssh/sshd_config
# Ciphers aes128-cbc,aes256-cbc
Replace the lines above with more secure ciphers such as 'aes256-ctr', 'chacha20-poly1305@openssh.com', or other preferred modern ciphers.
sudo service ssh restart
Conclusion:
Disabling CBC ciphers on the FortiSIEM virtual appliance is a proactive step to enhance security and protect against potential cryptographic vulnerabilities. By modifying the SSH configuration file and replacing CBC ciphers with more secure alternatives, it is possible to strengthen the encryption used for remote access to the FortiSIEM system. Always exercise caution when editing configuration files, and perform these changes during a maintenance window to minimize disruption to FortiSIEM operations. For further security enhancements and best practices, refer to the FortiSIEM documentation and consider staying up-to-date with the latest security recommendations. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.