Skip to content

Fortinet FortiGate Firewall Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-NET-000364-FW-000031

    Group
  • The FortiGate firewall must apply ingress filters to traffic that is inbound to the network through any active external interface.

    Unrestricted traffic to the trusted networks may contain malicious traffic that poses a threat to an enclave or to other connected networks. Additionally, unrestricted traffic may transit a network...
    Rule Medium Severity
  • SRG-NET-000364-FW-000032

    Group
  • SRG-NET-000364-FW-000035

    Group
  • When employed as a premise firewall, FortiGate must block all outbound management traffic.

    The management network must still have its own subnet in order to enforce control and access boundaries provided by layer 3 network nodes such as routers and firewalls. Management traffic between t...
    Rule Medium Severity
  • SRG-NET-000364-FW-000036

    Group
  • The FortiGate firewall must restrict traffic entering the VPN tunnels to the management network to only the authorized management packets based on destination address.

    Protect the management network with a filtering firewall configured to block unauthorized traffic. This requirement is similar to the out-of-band management (OOBM) model, in which the production ne...
    Rule Medium Severity
  • SRG-NET-000364-FW-000040

    Group
  • The FortiGate firewall must be configured to inspect all inbound and outbound traffic at the application layer.

    Application inspection enables the firewall to control traffic based on different parameters that exist within the packets such as enforcing application-specific message and field length. Inspectio...
    Rule Medium Severity
  • SRG-NET-000364-FW-000042

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules