Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
WEER
New Contributor

Poodle attack

Dear All,

I have fortigate 800c(version 5.00556) and IPS signature has expired and in the process of renewing.

There is a poodle vulnerability and it will solve with 5.587..

My question is ..1)is it possible to update without renewing?

                        2)from where can I download this 5.587 ?

                        3)if it is not possible to download wihout renewing..can we get temporally signature till it get renewed?

 

Thanks 

 

1 Solution
ede_pfau
SuperUser
SuperUser

hi,

 

without a valid subscription the FGT will not update automatically.

You may try to download the signature file manually. Go to fortinet.com, Service&Support, and log in to your account. Then Downloads, Fortiguard updates. Select the FortiOS version which is running and download the 'nids' file.

In the WebGUI of the FGT, go to Config, Fortiguard, find the IPS section and update manually.

 

All this depends on whether your account will still be granting you access.

 

Aside from this, contract renewals often take only 1-2 days from order to execution. I have even experienced putting in an order at 3 pm and getting the renewal registered by 5 pm on the same day.


Ede

"Kernel panic: Aiee, killing interrupt handler!"

View solution in original post

Ede"Kernel panic: Aiee, killing interrupt handler!"
5 REPLIES 5
Christopher_McMullan

I won't post the signature here, since (as far as I know) it hasn't been made public as a separate item. However, you can open a TAC ticket to request it for yourself.

 

You cannot update without a valid license, so to receive the signature automatically, you would have to wait for the renewal process to finish.

 

The FortiGuard Advisory on the POODLE vulnerability (http://www.fortiguard.com/advisory/CVE-2014-8730--Poodle-for-TLS--vulnerability/) does also mention another possibility as a workaround: disabling hardware acceleration. The attack will not proceed when the traffic is directed through the CPU instead. Please see the advisory for more details.

Regards, Chris McMullan Fortinet Ottawa

ede_pfau
SuperUser
SuperUser

hi,

 

without a valid subscription the FGT will not update automatically.

You may try to download the signature file manually. Go to fortinet.com, Service&Support, and log in to your account. Then Downloads, Fortiguard updates. Select the FortiOS version which is running and download the 'nids' file.

In the WebGUI of the FGT, go to Config, Fortiguard, find the IPS section and update manually.

 

All this depends on whether your account will still be granting you access.

 

Aside from this, contract renewals often take only 1-2 days from order to execution. I have even experienced putting in an order at 3 pm and getting the renewal registered by 5 pm on the same day.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
WEER
New Contributor

 

Hi Ede,

I will try this..Since this is an update of IPS ,hope I can do this during working hours without any down time?

Thanks a lot

 

WEER
New Contributor

dear Ede,

Can you tell whether I need a downtime for this update?Need any restart after the update??

 

Waiting for your response

ede_pfau
SuperUser
SuperUser

hi,

 

and sorry, I was asleep at night :) (CET here)

 

Absolutely, the update does not require any downtime. CPU load might peak but that doesn't matter.

While you're at it, update the AV signatures as well.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors