Had Fortigate set to automatic firmware updates. On Dec 11th, last update did three things that no update should do:
The default DH Group when creating a IPSec connection in Forticlient is 5 which is what we were using.
Why are you changing my routers settings without my consent? And changing integral settings so as to render VPN connections useless. It took four days to figure out what was going on.
Unacceptable in my opinion. It is my hardware. It is my configuration. At least ask me to make those changes for security reasons.
Unfortunately, everything works great after the hardware upgrade. The 101 gen1 has 4GB RAM, the IPS db has increased by so much, the only option was to ignore certain traffic or get something with more mem. I have a bunch of 40Fs that are currently doing the same thing, conserve mode at least once a week. So I am planning to take the 101s I just replaced and swap them for the 40F as a temp fix until I can budget for 91Gs.
DH group 5 based on a 1536 bit prime number isn't really secure enough any more. DH group 14 based on a 2048 bit prime is an absolute minimum, with DH group 20 based on ECP384 being both stronger and much faster.
| User | Count |
|---|---|
| 2882 | |
| 1446 | |
| 843 | |
| 822 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.