2.4.8 Virtual patching on the local-in management interface

Information

Allow virtual patching to be applied to traffic destined to the FortiGate by applying IPS signatures to the local in interface using local in policies. Attacks geared towards GUI and SSH management access, for example, can be mitigated using IPS signatures pushed from FortiGuard, thereby virtually patching these vulnerabilities.

Patches require scheduling of downtime, which means there is some attack window from the time Fortinet announced the vulnerability to when patch is applied. To minimise the risk, virtual patching on GUI and SSH management access is needed.

Solution

On CLI:

config firewall local-in-policy
edit <id>
set virtual-patch enable
next
end

See Also

https://workbench.cisecurity.org/benchmarks/15284

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CA-5, 800-53|RA-1, 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: FortiGate

Control ID: e871e9006a76aa698da8044f6027d3238821201c8fba28e72831ff8421fa66b8