Fortigate - Obfuscate HTTP headers

Information

The FortiGate unit can obfuscate the HTTP header information being sent to external web servers to better cloak the source.

Solution

To obfuscate HTTP headers, use the following CLI command:

config system global
set http-obfuscate {none |header-only | modified | no-error}
end

Where:
none - do not hide the FortiGate web server identity.
header-only - hides the HTTP server banner.
modified - provides modified error responses.
no-error - suppresses error responses

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-30

Plugin: FortiGate

Control ID: b9f6ae272092bfb94e9a9b8e3d7977d73345be1f17133ca7311a93e668b2a3f0