CIS Fortinet FortiGate Benchmark

Secure configuration guidelines for Fortinet FortiGate next-generation firewall

v1.3.0 December 2024

Overview

▶

This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Fortinet FortiGate. Recommendations cover system administration, user authentication, firewall policies, VPN configuration, logging and monitoring, and intrusion prevention.

~130Recommendations
6Sections
2Profile Levels
SectionAreaFocus
1AdministrationHostname, NTP, firmware
2AuthenticationAdmin accounts, lockout
3PoliciesFirewall rules, profiles
4VPNIPsec, SSL VPN
5LoggingSyslog, SNMP, alerts
6IPS/DoSIntrusion prevention

Profile Definitions

▶
ProfileDescriptionIntended Use
L1Level 1 — StandardEssential security for all Fortinet FortiGate deployments; minimal performance impact.
L2Level 2 — HardenedAdvanced hardening for PCI-DSS, HIPAA, or high-security environments.

1 — System Administration

▶

1.1 General Settings

▶
1.1.1 Ensure Device Hostname Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Device Hostname Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Device Hostname Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Device Hostname Is Configured. Apply the setting via CLI or management GUI and save the configuration.

1.1.2 Ensure NTP Is Configured with Trusted Sources (Automated)
L1 Auto
Description

This recommendation verifies that NTP Is Configured with Trusted Sources on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that NTP Is Configured with Trusted Sources. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure NTP Is Configured with Trusted Sources. Apply the setting via CLI or management GUI and save the configuration.

1.1.3 Ensure Login Banner Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Login Banner Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Login Banner Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Login Banner Is Configured. Apply the setting via CLI or management GUI and save the configuration.

1.1.4 Ensure DNS Servers Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that DNS Servers Are Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that DNS Servers Are Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure DNS Servers Are Configured. Apply the setting via CLI or management GUI and save the configuration.

1.2 Firmware & Hardening

▶
1.2.1 Ensure Latest Firmware Is Installed (Manual)
L1 Manual
Description

This recommendation verifies that Latest Firmware Is Installed on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Latest Firmware Is Installed. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Latest Firmware Is Installed. Apply the setting via CLI or management GUI and save the configuration.

1.2.2 Ensure Maintenance Mode Access Is Secured (Automated)
L1 Auto
Description

This recommendation verifies that Maintenance Mode Access Is Secured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Maintenance Mode Access Is Secured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Maintenance Mode Access Is Secured. Apply the setting via CLI or management GUI and save the configuration.

1.2.3 Ensure USB Auto-Install Is Disabled (Automated)
L1 Auto
Description

This recommendation verifies that USB Auto-Install Is Disabled on the Fortinet FortiGate firewall. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Fortinet FortiGate firewall increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Review the Fortinet FortiGate device configuration and verify that USB Auto-Install Is Disabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure USB Auto-Install Is Disabled. Apply the setting via CLI or management GUI and save the configuration.

1.2.4 Ensure Console Port Timeout Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Console Port Timeout Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Console Port Timeout Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Console Port Timeout Is Configured. Apply the setting via CLI or management GUI and save the configuration.

2 — Authentication & Access Control

▶

2.1 Admin Accounts

▶
2.1.1 Ensure Default Admin Password Is Changed (Manual)
L1 Manual
Description

This recommendation verifies that Default Admin Password Is Changed on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Default Admin Password Is Changed. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Default Admin Password Is Changed. Apply the setting via CLI or management GUI and save the configuration.

2.1.2 Ensure Admin Profiles Are Configured with Least Privilege (Manual)
L1 Manual
Description

This recommendation verifies that Admin Profiles Are Configured with Least Privilege on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Admin Profiles Are Configured with Least Privilege. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Admin Profiles Are Configured with Least Privilege. Apply the setting via CLI or management GUI and save the configuration.

2.1.3 Ensure Trusted Hosts Are Configured for Admin Accounts (Automated)
L1 Auto
Description

This recommendation verifies that Trusted Hosts Are Configured for Admin Accounts on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Trusted Hosts Are Configured for Admin Accounts. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Trusted Hosts Are Configured for Admin Accounts. Apply the setting via CLI or management GUI and save the configuration.

2.1.4 Ensure Two-Factor Authentication Is Enabled for Admins (Automated)
L2 Auto
Description

This recommendation verifies that Two-Factor Authentication Is Enabled for Admins on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Two-Factor Authentication Is Enabled for Admins. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Two-Factor Authentication Is Enabled for Admins. Apply the setting via CLI or management GUI and save the configuration.

2.2 Authentication Settings

▶
2.2.1 Ensure Admin Lockout Policy Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Admin Lockout Policy Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Admin Lockout Policy Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Admin Lockout Policy Is Configured. Apply the setting via CLI or management GUI and save the configuration.

2.2.2 Ensure Idle Session Timeout Is Set (Automated)
L1 Auto
Description

This recommendation verifies that Idle Session Timeout Is Set on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Idle Session Timeout Is Set. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Idle Session Timeout Is Set. Apply the setting via CLI or management GUI and save the configuration.

2.2.3 Ensure Strong Password Policy Is Enforced (Automated)
L1 Auto
Description

This recommendation ensures that Strong Password Policy Is Enforced on the Fortinet FortiGate firewall. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Fortinet FortiGate firewall may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

Review the Fortinet FortiGate device configuration and verify that Strong Password Policy Is Enforced. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Strong Password Policy Is Enforced. Apply the setting via CLI or management GUI and save the configuration.

2.2.4 Ensure RADIUS or LDAP Authentication Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that RADIUS or LDAP Authentication Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that RADIUS or LDAP Authentication Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure RADIUS or LDAP Authentication Is Configured. Apply the setting via CLI or management GUI and save the configuration.

3 — Firewall Policies

▶

3.1 Policy Configuration

▶
3.1.1 Ensure Implicit Deny Policy Exists (Automated)
L1 Auto
Description

This recommendation verifies that Implicit Deny Policy Exists on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Implicit Deny Policy Exists. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Implicit Deny Policy Exists. Apply the setting via CLI or management GUI and save the configuration.

3.1.2 Ensure No Any-Any-Any-Allow Policy Exists (Automated)
L1 Auto
Description

This recommendation verifies that No Any-Any-Any-Allow Policy Exists on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that No Any-Any-Any-Allow Policy Exists. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure No Any-Any-Any-Allow Policy Exists. Apply the setting via CLI or management GUI and save the configuration.

3.1.3 Ensure Unused Policies Are Removed (Manual)
L1 Manual
Description

This recommendation verifies that Unused Policies Are Removed on the Fortinet FortiGate firewall. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Fortinet FortiGate firewall increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Review the Fortinet FortiGate device configuration and verify that Unused Policies Are Removed. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Unused Policies Are Removed. Apply the setting via CLI or management GUI and save the configuration.

3.1.4 Ensure Policy Logging Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Policy Logging Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Policy Logging Is Enabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Policy Logging Is Enabled. Apply the setting via CLI or management GUI and save the configuration.

3.2 Security Profiles

▶
3.2.1 Ensure Antivirus Profile Is Applied to Policies (Automated)
L1 Auto
Description

This recommendation verifies that Antivirus Profile Is Applied to Policies on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Antivirus Profile Is Applied to Policies. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Antivirus Profile Is Applied to Policies. Apply the setting via CLI or management GUI and save the configuration.

3.2.2 Ensure Web Filter Profile Is Applied to Policies (Automated)
L1 Auto
Description

This recommendation verifies that Web Filter Profile Is Applied to Policies on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Web Filter Profile Is Applied to Policies. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Web Filter Profile Is Applied to Policies. Apply the setting via CLI or management GUI and save the configuration.

3.2.3 Ensure Application Control Is Applied to Policies (Automated)
L1 Auto
Description

This recommendation verifies that Application Control Is Applied to Policies on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Application Control Is Applied to Policies. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Application Control Is Applied to Policies. Apply the setting via CLI or management GUI and save the configuration.

3.2.4 Ensure SSL Inspection Is Configured (Manual)
L2 Manual
Description

This recommendation verifies that SSL Inspection Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that SSL Inspection Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure SSL Inspection Is Configured. Apply the setting via CLI or management GUI and save the configuration.

4 — VPN Configuration

▶

4.1 IPsec VPN

▶
4.1.1 Ensure IKE Version 2 Is Preferred (Automated)
L1 Auto
Description

This recommendation verifies that IKE Version 2 Is Preferred on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that IKE Version 2 Is Preferred. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure IKE Version 2 Is Preferred. Apply the setting via CLI or management GUI and save the configuration.

4.1.2 Ensure Strong Phase 1 Encryption Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Strong Phase 1 Encryption Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Strong Phase 1 Encryption Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Strong Phase 1 Encryption Is Configured. Apply the setting via CLI or management GUI and save the configuration.

4.1.3 Ensure Strong Phase 2 Encryption Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Strong Phase 2 Encryption Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Strong Phase 2 Encryption Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Strong Phase 2 Encryption Is Configured. Apply the setting via CLI or management GUI and save the configuration.

4.1.4 Ensure Dead Peer Detection Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Dead Peer Detection Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Dead Peer Detection Is Enabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Dead Peer Detection Is Enabled. Apply the setting via CLI or management GUI and save the configuration.

4.2 SSL VPN

▶
4.2.1 Ensure SSL VPN Uses TLS 1.2 or Higher (Automated)
L1 Auto
Description

This recommendation verifies that SSL VPN Uses TLS 1.2 or Higher on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that SSL VPN Uses TLS 1.2 or Higher. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure SSL VPN Uses TLS 1.2 or Higher. Apply the setting via CLI or management GUI and save the configuration.

4.2.2 Ensure SSL VPN Portal Requires Authentication (Automated)
L1 Auto
Description

This recommendation ensures that SSL VPN Portal Requires Authentication on the Fortinet FortiGate firewall. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Fortinet FortiGate firewall may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

Review the Fortinet FortiGate device configuration and verify that SSL VPN Portal Requires Authentication. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure SSL VPN Portal Requires Authentication. Apply the setting via CLI or management GUI and save the configuration.

4.2.3 Ensure Split Tunneling Is Disabled (Automated)
L2 Auto
Description

This recommendation verifies that Split Tunneling Is Disabled on the Fortinet FortiGate firewall. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Fortinet FortiGate firewall increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Review the Fortinet FortiGate device configuration and verify that Split Tunneling Is Disabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Split Tunneling Is Disabled. Apply the setting via CLI or management GUI and save the configuration.

4.2.4 Ensure SSL VPN Idle Timeout Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that SSL VPN Idle Timeout Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that SSL VPN Idle Timeout Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure SSL VPN Idle Timeout Is Configured. Apply the setting via CLI or management GUI and save the configuration.

5 — Logging & Monitoring

▶

5.1 Log Configuration

▶
5.1.1 Ensure Remote Logging to FortiAnalyzer or Syslog Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Remote Logging to FortiAnalyzer or Syslog Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Remote Logging to FortiAnalyzer or Syslog Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Remote Logging to FortiAnalyzer or Syslog Is Configured. Apply the setting via CLI or management GUI and save the configuration.

5.1.2 Ensure Traffic Logging Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Traffic Logging Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Traffic Logging Is Enabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Traffic Logging Is Enabled. Apply the setting via CLI or management GUI and save the configuration.

5.1.3 Ensure Event Logging Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Event Logging Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Event Logging Is Enabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Event Logging Is Enabled. Apply the setting via CLI or management GUI and save the configuration.

5.1.4 Ensure Log Encryption Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that Log Encryption Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Log Encryption Is Enabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Log Encryption Is Enabled. Apply the setting via CLI or management GUI and save the configuration.

5.2 Alerting & SNMP

▶
5.2.1 Ensure SNMP Community Strings Are Changed (Automated)
L1 Auto
Description

This recommendation verifies that SNMP Community Strings Are Changed on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that SNMP Community Strings Are Changed. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure SNMP Community Strings Are Changed. Apply the setting via CLI or management GUI and save the configuration.

5.2.2 Ensure SNMPv3 Is Used (Automated)
L2 Auto
Description

This recommendation verifies that SNMPv3 Is Used on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that SNMPv3 Is Used. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure SNMPv3 Is Used. Apply the setting via CLI or management GUI and save the configuration.

5.2.3 Ensure Alert Email Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Alert Email Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Alert Email Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Alert Email Is Configured. Apply the setting via CLI or management GUI and save the configuration.

6 — Intrusion Prevention & DoS

▶

6.1 IPS Configuration

▶
6.1.1 Ensure IPS Sensor Is Applied to Policies (Automated)
L1 Auto
Description

This recommendation verifies that IPS Sensor Is Applied to Policies on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that IPS Sensor Is Applied to Policies. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure IPS Sensor Is Applied to Policies. Apply the setting via CLI or management GUI and save the configuration.

6.1.2 Ensure IPS Signatures Are Updated (Automated)
L1 Auto
Description

This recommendation verifies that IPS Signatures Are Updated on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that IPS Signatures Are Updated. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure IPS Signatures Are Updated. Apply the setting via CLI or management GUI and save the configuration.

6.1.3 Ensure Botnet C&C Detection Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Botnet C&C Detection Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Botnet C&C Detection Is Enabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Botnet C&C Detection Is Enabled. Apply the setting via CLI or management GUI and save the configuration.

6.2 DoS Protection

▶
6.2.1 Ensure DoS Policy Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that DoS Policy Is Configured on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that DoS Policy Is Configured. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure DoS Policy Is Configured. Apply the setting via CLI or management GUI and save the configuration.

6.2.2 Ensure Anomaly-Based Detection Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that Anomaly-Based Detection Is Enabled on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Anomaly-Based Detection Is Enabled. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Anomaly-Based Detection Is Enabled. Apply the setting via CLI or management GUI and save the configuration.

6.2.3 Ensure Rate Limiting Is Applied to Critical Interfaces (Automated)
L2 Auto
Description

This recommendation verifies that Rate Limiting Is Applied to Critical Interfaces on the Fortinet FortiGate firewall. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Fortinet FortiGate firewall vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Review the Fortinet FortiGate device configuration and verify that Rate Limiting Is Applied to Critical Interfaces. Use the CLI or management GUI to confirm the setting is applied.

Remediation

Configure the Fortinet FortiGate device configuration to ensure Rate Limiting Is Applied to Critical Interfaces. Apply the setting via CLI or management GUI and save the configuration.