DROWN vulnerability on SSL/TLS was made public today with good information at https://drownattack.com.
I'm looking for info from Fortinet/FortiGuard on how/if FortiWeb does/can mitigate this vulnerability.
Comments?
Norris Carden
Fortinet XTreme Team USA (2015, 2016)
CISSP (2005), CISA (2007), NSE4 (2016)
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
+1
I'm running several devices with v5 p10 load and wondering if the SSL VPN, web admin or any other functionality is affected by this exploit.
This vulnerability only affect SSLv2 servers.
To disable this kind of cipher on Fortigate, you can do it on CLI:
# config system global
# set strong-crypto enable
# end
If you have some server behind Fortigate, you will need waiting, because has no IPS signature until now.
Regards,
Paulo Raponi, NSE8
Regards, Paulo Raponi
When will Fortinet be releasing an updated signature for this? Is it possible to create one?
This is posted in the wrong location. This is the FortiWeb forum. Not FortiGuard/FortiGate.
Specifically for FortiWeb when deployed in reverse proxy or True transparent proxy all web servers behind it are protected.
Idan Soen wrote:This is posted in the wrong location. This is the FortiWeb forum. Not FortiGuard/FortiGate.
This is NOT in the wrong location. Please see the original post:
CyberNorris wrote:I'm looking for info from Fortinet/FortiGuard on how/if FortiWeb does/can mitigate this vulnerability.
Idan Soen wrote:Specifically for FortiWeb when deployed in reverse proxy or True transparent proxy all web servers behind it are protected.
Thank you. I suspected that FortiWeb would protect any systems with SSL/TLS offload on the FortiWeb as it doesn't even have the option to support SSL v2.
What levels of SSL/TLS does the FortiWeb web admin utilize?
Norris Carden
Fortinet XTreme Team USA (2015, 2016)
CISSP (2005), CISA (2007), NSE4 (2016)
I am looking for information on this, as well. I would like to know whether we can globally disable ssl v2. I can see that our servers are currently vulnerable.
will enabling the strong crypto on via cli prevent this ?
Or can we mitigate by enabling SSL inspection ?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.