TNS Fortigate FortiOS Best Practices

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: TNS Fortigate FortiOS Best Practices

Updated: 11/3/2020

Authority: TNS

Plugin: FortiGate

Revision: 1.34

Estimated Item Count: 91

File Details

Filename: TNS_Fortigate_Best_Practices.audit

Size: 87.7 kB

Audit Items

DescriptionCategories
Alertmail server not configured or this feature is not available on the device
Auto Backup via central management is not available or not configured.
Event Logging is not available or enabled - Event Logging category checks not performed
Fortigate - AAA - LDAP server is trusted

IDENTIFICATION AND AUTHENTICATION

Fortigate - AAA - RADIUS server is trusted

IDENTIFICATION AND AUTHENTICATION

Fortigate - AAA - TACACS+ server is trusted

IDENTIFICATION AND AUTHENTICATION

Fortigate - Access Banner is enabled

ACCESS CONTROL

Fortigate - Admin access - trusted hosts

ACCESS CONTROL

Fortigate - Admin password lockout >= 300 seconds

ACCESS CONTROL

Fortigate - Admin password lockout threshold - '1'

ACCESS CONTROL

Fortigate - Alert Emails - 'admin address'

SYSTEM AND INFORMATION INTEGRITY

Fortigate - Antispam License - Not Expired

CONFIGURATION MANAGEMENT

Fortigate - Auto backup is configured - 'FortiManager'

CONTINGENCY PLANNING

Fortigate - AV Grayware

SYSTEM AND INFORMATION INTEGRITY

Fortigate - AV Heuristic - 'block'

SYSTEM AND INFORMATION INTEGRITY

Fortigate - AV License - Not Expired

CONFIGURATION MANAGEMENT

Fortigate - Disable insecure services - HTTP

CONFIGURATION MANAGEMENT

Fortigate - Disable insecure services - TELNET

CONFIGURATION MANAGEMENT

Fortigate - Disable SSHv1 admin access

CONFIGURATION MANAGEMENT

Fortigate - DNS - primary server

SYSTEM AND COMMUNICATIONS PROTECTION

Fortigate - DNS - secondary server

SYSTEM AND COMMUNICATIONS PROTECTION

Fortigate - Does not use self-signed certificate - 'admin'

IDENTIFICATION AND AUTHENTICATION

Fortigate - Does not use self-signed certificate - 'user'

IDENTIFICATION AND AUTHENTICATION

Fortigate - Enable logs of failed connection attempts

AUDIT AND ACCOUNTABILITY

Fortigate - Ensure default admin usernames are not used

ACCESS CONTROL

Fortigate - External Logging - 'fortianalyzer'

AUDIT AND ACCOUNTABILITY

Fortigate - External Logging - 'fortianalyzer2'

AUDIT AND ACCOUNTABILITY

Fortigate - External Logging - 'fortianalyzer3'

AUDIT AND ACCOUNTABILITY

Fortigate - External Logging - 'syslog2'

AUDIT AND ACCOUNTABILITY

Fortigate - External Logging - 'syslog3'

AUDIT AND ACCOUNTABILITY

Fortigate - External Logging - 'syslogd'

AUDIT AND ACCOUNTABILITY

Fortigate - Fortianalyzer Logs - severity 'information'

AUDIT AND ACCOUNTABILITY

Fortigate - Fortianalyzer2 Logs - severity 'information'

AUDIT AND ACCOUNTABILITY

Fortigate - Fortianalyzer3 Logs - severity 'information'

AUDIT AND ACCOUNTABILITY

Fortigate - full-final-warning-threshold <= 95%

AUDIT AND ACCOUNTABILITY

Fortigate - full-first-warning-threshold <= 75%

AUDIT AND ACCOUNTABILITY

Fortigate - full-second-warning-threshold <= 90%

AUDIT AND ACCOUNTABILITY

Fortigate - HTTPS/SSH admin access strong ciphers

ACCESS CONTROL

Fortigate - Inactivity timeout - 'console' <= 5

ACCESS CONTROL

Fortigate - Inactivity timeout - 'console' <= 300

ACCESS CONTROL

Fortigate - Inactivity timeout - 'global' <= 5

ACCESS CONTROL

Fortigate - IPS database - extended

SYSTEM AND INFORMATION INTEGRITY

Fortigate - Local Logging - severity 'information'

AUDIT AND ACCOUNTABILITY

Fortigate - Local Logging is enabled

AUDIT AND ACCOUNTABILITY

Fortigate - Log admin login/logout messages

AUDIT AND ACCOUNTABILITY

Fortigate - Log DNS lookups

AUDIT AND ACCOUNTABILITY

Fortigate - Log network messages

AUDIT AND ACCOUNTABILITY

Fortigate - Log user authentication messages

AUDIT AND ACCOUNTABILITY

Fortigate - Log UTM messages

AUDIT AND ACCOUNTABILITY

Fortigate - Log WAN optimization messages

AUDIT AND ACCOUNTABILITY