4.3.3 Apply DNS Filter Security Profile to Policies

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Ensuring that traffic traversing to the Internet on the FortiGate has a DNS Filter security profile inspecting it.

Rationale:

Traffic outbound to the Internet on the FortiGate should have firewall policies applied with an DNS Filter security profile applied.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure on 'Allowed' firewall policies that handle traffic outbound to Internet to have an appropriate DNS Filter security profile applied to policies.

Default Value:

Not Configured

See Also

https://workbench.cisecurity.org/benchmarks/12961