7.2.1 Encrypt Log Transmission to FortiAnalyzer / FortiManager

Information

Enable encryption for logs that are sent to FortiAnalyzer or FortiManager.

Provides encryption for logs that are sent to FortiAnalyzer or FortiManager to prevent logs being collected and viewed as they traverse the network.

Solution

Secure log transfer settings can only be configured on CLI:

config log fortianalyzer setting
set reliable enable
set enc-algorithm high
end

See Also

https://workbench.cisecurity.org/benchmarks/15284

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: FortiGate

Control ID: 32efcbd1adaab0da33d718d274bef721e6f528866881f1318c0906dd509338e4