We bought some Firewalls 81F, but unfortunately they all have BLE inbuilt and it is not possible to go through TEMPEST screening. Is it possible to remove inbuilt BLE? Thank you.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Physical intervention on the device could potentially void the RMA policy. Technically the BLE will be running only for a minute during the first boot/initialization. If the device is configured without using the BLE, it should remain turned off as shown also in the configuration guide. I don't have an appliance to test it, the command should be:
config system global
set ble-module disable
A reboot may be required for the changes to take effect. The status of BLE can be checked by the flashing of the status LED.
I managed to find a 81F in a lab and it seems that the previous command (in 7.4.5) is not present. The following command disables Bluetooth/BLE:
# diagnose bluetooth enable 0
Disable Bluetooth
The status can be checked with:
# diagnose bluetooth status
Bluetooth Status: RESET BOOTLOADER
Connect State(0): BLE_MODE_DISABLED
If the status is manually changed to 'enable 1' it will stay enabled only for a minute:
# diagnose bluetooth status
Bluetooth Status: NORMAL BOOTLOADER
Connect State(5): BLE_MODE_FSD_READY
Are you trying to find a way to disable BLE or physically detach the module in order to pass the device screening?
I prefer physically detach, but if there is a way to disable BLE and not beeing seen in TEMPEST laboratory, I would be happy.
Physical intervention on the device could potentially void the RMA policy. Technically the BLE will be running only for a minute during the first boot/initialization. If the device is configured without using the BLE, it should remain turned off as shown also in the configuration guide. I don't have an appliance to test it, the command should be:
config system global
set ble-module disable
A reboot may be required for the changes to take effect. The status of BLE can be checked by the flashing of the status LED.
We will try to disable BLE and bring that one to TEMPEST lab to test if they see it. Thank you.
I managed to find a 81F in a lab and it seems that the previous command (in 7.4.5) is not present. The following command disables Bluetooth/BLE:
# diagnose bluetooth enable 0
Disable Bluetooth
The status can be checked with:
# diagnose bluetooth status
Bluetooth Status: RESET BOOTLOADER
Connect State(0): BLE_MODE_DISABLED
If the status is manually changed to 'enable 1' it will stay enabled only for a minute:
# diagnose bluetooth status
Bluetooth Status: NORMAL BOOTLOADER
Connect State(5): BLE_MODE_FSD_READY
Now I will wait answer from a tempest lab. Thank you.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.