Fortigate - Disable insecure services - HTTP

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

HTTP is insecure by nature as it sends all traffic across the wire in clear text.

Solution

Use the following command to specific access protocols for a given interface:

config system interface
edit <interface_name>
set allowaccess <protocols>
end

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1

Plugin: FortiGate

Control ID: d59af2d1616bddc6297851b699e3a797f67c7ad2255fe9d97f238df9cbf5266f