4.3.3 Apply DNS Filter Security Profile to Policies

Information

Ensuring that traffic traversing to the Internet on the FortiGate has a DNS Filter security profile inspecting it.

Traffic outbound to the Internet on the FortiGate should have firewall policies applied with an DNS Filter security profile applied.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure on "Allowed" firewall policies that handle traffic outbound to Internet to have an appropriate DNS Filter security profile applied to policies.

See Also

https://workbench.cisecurity.org/benchmarks/15284

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: FortiGate

Control ID: 8772955327d1297db9cc9156c11f8b0c24d8ba2f44a653bf3ed60b51d26d67fb