Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CyberNorris
New Contributor III

DROWN vulnerability mitigation?

DROWN vulnerability on SSL/TLS was made public today with good information at https://drownattack.com.

 

I'm looking for info from Fortinet/FortiGuard on how/if FortiWeb does/can mitigate this vulnerability.

 

Comments?

Norris Carden

Fortinet XTreme Team USA (2015, 2016)

CISSP (2005), CISA (2007), NSE4 (2016)

Norris Carden Fortinet XTreme Team USA (2015, 2016) CISSP (2005), CISA (2007), NSE4 (2016)
6 REPLIES 6
paradoxum
New Contributor

+1

 

I'm running several devices with v5 p10 load and wondering if the SSL VPN, web admin or any other functionality is affected by this exploit.

pcraponi

This vulnerability only affect SSLv2 servers.

 

To disable this kind of cipher on Fortigate, you can do it on CLI:

 

# config system global

#   set strong-crypto enable

# end

 

If you have some server behind Fortigate, you will need waiting, because has no IPS signature until now.

 

Regards,

Paulo Raponi, NSE8

Regards, Paulo Raponi

Regards, Paulo Raponi
fortitrolol

When will Fortinet be releasing an updated signature for this?  Is it possible to create one?

Idan_Soen_FTNT

This is posted in the wrong location. This is the FortiWeb forum. Not FortiGuard/FortiGate.

Specifically for FortiWeb when deployed in reverse proxy or True transparent proxy all web servers behind it are protected.

CyberNorris

Idan Soen wrote:

This is posted in the wrong location. This is the FortiWeb forum. Not FortiGuard/FortiGate.

 

This is NOT in the wrong location. Please see the original post:

 

CyberNorris wrote:

I'm looking for info from Fortinet/FortiGuard on how/if FortiWeb does/can mitigate this vulnerability.

 

Idan Soen wrote:

Specifically for FortiWeb when deployed in reverse proxy or True transparent proxy all web servers behind it are protected.

 

Thank you. I suspected that FortiWeb would protect any systems with SSL/TLS offload on the FortiWeb as it doesn't even have the option to support SSL v2.

 

What levels of SSL/TLS does the FortiWeb web admin utilize?

Norris Carden

Fortinet XTreme Team USA (2015, 2016)

CISSP (2005), CISA (2007), NSE4 (2016)

Norris Carden Fortinet XTreme Team USA (2015, 2016) CISSP (2005), CISA (2007), NSE4 (2016)
Spartacus1988
New Contributor

I am looking for information on this, as well. I would like to know whether we can globally disable ssl v2. I can see that our servers are currently vulnerable. 

 

will enabling the strong crypto on via cli prevent this ? 

 

Or can we mitigate by enabling SSL inspection ? 

 

Labels
Top Kudoed Authors