We bought some Firewalls 81F, but unfortunately they all have BLE inbuilt and it is not possible to go through TEMPEST screening. Is it possible to remove inbuilt BLE? Thank you.
Solved! Go to Solution.
Physical intervention on the device could potentially void the RMA policy. Technically the BLE will be running only for a minute during the first boot/initialization. If the device is configured without using the BLE, it should remain turned off as shown also in the configuration guide. I don't have an appliance to test it, the command should be:
config system global
set ble-module disable
A reboot may be required for the changes to take effect. The status of BLE can be checked by the flashing of the status LED.
I managed to find a 81F in a lab and it seems that the previous command (in 7.4.5) is not present. The following command disables Bluetooth/BLE:
# diagnose bluetooth enable 0
Disable Bluetooth
The status can be checked with:
# diagnose bluetooth status
Bluetooth Status: RESET BOOTLOADER
Connect State(0): BLE_MODE_DISABLED
If the status is manually changed to 'enable 1' it will stay enabled only for a minute:
# diagnose bluetooth status
Bluetooth Status: NORMAL BOOTLOADER
Connect State(5): BLE_MODE_FSD_READY
Are you trying to find a way to disable BLE or physically detach the module in order to pass the device screening?
I prefer physically detach, but if there is a way to disable BLE and not beeing seen in TEMPEST laboratory, I would be happy.
Physical intervention on the device could potentially void the RMA policy. Technically the BLE will be running only for a minute during the first boot/initialization. If the device is configured without using the BLE, it should remain turned off as shown also in the configuration guide. I don't have an appliance to test it, the command should be:
config system global
set ble-module disable
A reboot may be required for the changes to take effect. The status of BLE can be checked by the flashing of the status LED.
We will try to disable BLE and bring that one to TEMPEST lab to test if they see it. Thank you.
I managed to find a 81F in a lab and it seems that the previous command (in 7.4.5) is not present. The following command disables Bluetooth/BLE:
# diagnose bluetooth enable 0
Disable Bluetooth
The status can be checked with:
# diagnose bluetooth status
Bluetooth Status: RESET BOOTLOADER
Connect State(0): BLE_MODE_DISABLED
If the status is manually changed to 'enable 1' it will stay enabled only for a minute:
# diagnose bluetooth status
Bluetooth Status: NORMAL BOOTLOADER
Connect State(5): BLE_MODE_FSD_READY
Now I will wait answer from a tempest lab. Thank you.
I’m truly surprised that Fortinet would incorporate this technology into a security device, fully aware that it doesn’t meet the security standards required by many data centers. We encountered the same issue with the 901Gs, which resulted in us being denied access to the data center. Simply disabling Bluetooth and the external button didn’t suffice to meet the security requirements. I sincerely hope these are removable modules, or else we’ll be left with expensive paperweights.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.