CIS Fortinet FortiGate Benchmark
Secure configuration guidelines for Fortinet FortiGate next-generation firewall
v1.3.0 December 2024Overview
▶This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Fortinet FortiGate. Recommendations cover system administration, user authentication, firewall policies, VPN configuration, logging and monitoring, and intrusion prevention.
| Section | Area | Focus |
|---|---|---|
| 1 | Administration | Hostname, NTP, firmware |
| 2 | Authentication | Admin accounts, lockout |
| 3 | Policies | Firewall rules, profiles |
| 4 | VPN | IPsec, SSL VPN |
| 5 | Logging | Syslog, SNMP, alerts |
| 6 | IPS/DoS | Intrusion prevention |
Profile Definitions
▶| Profile | Description | Intended Use |
|---|---|---|
| L1 | Level 1 — Standard | Essential security for all Fortinet FortiGate deployments; minimal performance impact. |
| L2 | Level 2 — Hardened | Advanced hardening for PCI-DSS, HIPAA, or high-security environments. |
1 — System Administration
▶1.1 General Settings
▶This recommendation verifies that Device Hostname Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Device Hostname Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Device Hostname Is Configured. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that NTP Is Configured with Trusted Sources on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that NTP Is Configured with Trusted Sources. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure NTP Is Configured with Trusted Sources. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Login Banner Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Login Banner Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Login Banner Is Configured. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that DNS Servers Are Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that DNS Servers Are Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure DNS Servers Are Configured. Apply the setting via CLI or management GUI and save the configuration.
1.2 Firmware & Hardening
▶This recommendation verifies that Latest Firmware Is Installed on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Latest Firmware Is Installed. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Latest Firmware Is Installed. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Maintenance Mode Access Is Secured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Maintenance Mode Access Is Secured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Maintenance Mode Access Is Secured. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that USB Auto-Install Is Disabled on the Fortinet FortiGate firewall. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Fortinet FortiGate firewall increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
Review the Fortinet FortiGate device configuration and verify that USB Auto-Install Is Disabled. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure USB Auto-Install Is Disabled. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Console Port Timeout Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Console Port Timeout Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Console Port Timeout Is Configured. Apply the setting via CLI or management GUI and save the configuration.
2 — Authentication & Access Control
▶2.1 Admin Accounts
▶This recommendation verifies that Default Admin Password Is Changed on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Default Admin Password Is Changed. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Default Admin Password Is Changed. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Admin Profiles Are Configured with Least Privilege on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Admin Profiles Are Configured with Least Privilege. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Admin Profiles Are Configured with Least Privilege. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Trusted Hosts Are Configured for Admin Accounts on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Trusted Hosts Are Configured for Admin Accounts. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Trusted Hosts Are Configured for Admin Accounts. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Two-Factor Authentication Is Enabled for Admins on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Two-Factor Authentication Is Enabled for Admins. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Two-Factor Authentication Is Enabled for Admins. Apply the setting via CLI or management GUI and save the configuration.
2.2 Authentication Settings
▶This recommendation verifies that Admin Lockout Policy Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Admin Lockout Policy Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Admin Lockout Policy Is Configured. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Idle Session Timeout Is Set on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Idle Session Timeout Is Set. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Idle Session Timeout Is Set. Apply the setting via CLI or management GUI and save the configuration.
This recommendation ensures that Strong Password Policy Is Enforced on the Fortinet FortiGate firewall. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Fortinet FortiGate firewall may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
Review the Fortinet FortiGate device configuration and verify that Strong Password Policy Is Enforced. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Strong Password Policy Is Enforced. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that RADIUS or LDAP Authentication Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that RADIUS or LDAP Authentication Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure RADIUS or LDAP Authentication Is Configured. Apply the setting via CLI or management GUI and save the configuration.
3 — Firewall Policies
▶3.1 Policy Configuration
▶This recommendation verifies that Implicit Deny Policy Exists on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Implicit Deny Policy Exists. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Implicit Deny Policy Exists. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that No Any-Any-Any-Allow Policy Exists on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that No Any-Any-Any-Allow Policy Exists. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure No Any-Any-Any-Allow Policy Exists. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Unused Policies Are Removed on the Fortinet FortiGate firewall. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Fortinet FortiGate firewall increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
Review the Fortinet FortiGate device configuration and verify that Unused Policies Are Removed. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Unused Policies Are Removed. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Policy Logging Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Policy Logging Is Enabled. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Policy Logging Is Enabled. Apply the setting via CLI or management GUI and save the configuration.
3.2 Security Profiles
▶This recommendation verifies that Antivirus Profile Is Applied to Policies on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Antivirus Profile Is Applied to Policies. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Antivirus Profile Is Applied to Policies. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Web Filter Profile Is Applied to Policies on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Web Filter Profile Is Applied to Policies. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Web Filter Profile Is Applied to Policies. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Application Control Is Applied to Policies on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Application Control Is Applied to Policies. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Application Control Is Applied to Policies. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that SSL Inspection Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that SSL Inspection Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure SSL Inspection Is Configured. Apply the setting via CLI or management GUI and save the configuration.
4 — VPN Configuration
▶4.1 IPsec VPN
▶This recommendation verifies that IKE Version 2 Is Preferred on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that IKE Version 2 Is Preferred. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure IKE Version 2 Is Preferred. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Strong Phase 1 Encryption Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Strong Phase 1 Encryption Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Strong Phase 1 Encryption Is Configured. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Strong Phase 2 Encryption Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Strong Phase 2 Encryption Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Strong Phase 2 Encryption Is Configured. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Dead Peer Detection Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Dead Peer Detection Is Enabled. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Dead Peer Detection Is Enabled. Apply the setting via CLI or management GUI and save the configuration.
4.2 SSL VPN
▶This recommendation verifies that SSL VPN Uses TLS 1.2 or Higher on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that SSL VPN Uses TLS 1.2 or Higher. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure SSL VPN Uses TLS 1.2 or Higher. Apply the setting via CLI or management GUI and save the configuration.
This recommendation ensures that SSL VPN Portal Requires Authentication on the Fortinet FortiGate firewall. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Fortinet FortiGate firewall may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
Review the Fortinet FortiGate device configuration and verify that SSL VPN Portal Requires Authentication. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure SSL VPN Portal Requires Authentication. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Split Tunneling Is Disabled on the Fortinet FortiGate firewall. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Fortinet FortiGate firewall increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
Review the Fortinet FortiGate device configuration and verify that Split Tunneling Is Disabled. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Split Tunneling Is Disabled. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that SSL VPN Idle Timeout Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that SSL VPN Idle Timeout Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure SSL VPN Idle Timeout Is Configured. Apply the setting via CLI or management GUI and save the configuration.
5 — Logging & Monitoring
▶5.1 Log Configuration
▶This recommendation verifies that Remote Logging to FortiAnalyzer or Syslog Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Remote Logging to FortiAnalyzer or Syslog Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Remote Logging to FortiAnalyzer or Syslog Is Configured. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Traffic Logging Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Traffic Logging Is Enabled. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Traffic Logging Is Enabled. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Event Logging Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Event Logging Is Enabled. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Event Logging Is Enabled. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Log Encryption Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Log Encryption Is Enabled. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Log Encryption Is Enabled. Apply the setting via CLI or management GUI and save the configuration.
5.2 Alerting & SNMP
▶This recommendation verifies that SNMP Community Strings Are Changed on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that SNMP Community Strings Are Changed. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure SNMP Community Strings Are Changed. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that SNMPv3 Is Used on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that SNMPv3 Is Used. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure SNMPv3 Is Used. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Alert Email Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Alert Email Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Alert Email Is Configured. Apply the setting via CLI or management GUI and save the configuration.
6 — Intrusion Prevention & DoS
▶6.1 IPS Configuration
▶This recommendation verifies that IPS Sensor Is Applied to Policies on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that IPS Sensor Is Applied to Policies. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure IPS Sensor Is Applied to Policies. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that IPS Signatures Are Updated on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that IPS Signatures Are Updated. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure IPS Signatures Are Updated. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Botnet C&C Detection Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Botnet C&C Detection Is Enabled. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Botnet C&C Detection Is Enabled. Apply the setting via CLI or management GUI and save the configuration.
6.2 DoS Protection
▶This recommendation verifies that DoS Policy Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that DoS Policy Is Configured. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure DoS Policy Is Configured. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Anomaly-Based Detection Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Anomaly-Based Detection Is Enabled. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Anomaly-Based Detection Is Enabled. Apply the setting via CLI or management GUI and save the configuration.
This recommendation verifies that Rate Limiting Is Applied to Critical Interfaces on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Review the Fortinet FortiGate device configuration and verify that Rate Limiting Is Applied to Critical Interfaces. Use the CLI or management GUI to confirm the setting is applied.
Configure the Fortinet FortiGate device configuration to ensure Rate Limiting Is Applied to Critical Interfaces. Apply the setting via CLI or management GUI and save the configuration.