Fortigate - Disable insecure services - HTTP

Information

HTTP is insecure by nature as it sends all traffic across the wire in clear text.

Solution

Use the following command to specific access protocols for a given interface:

config system interface
edit <interface_name>
set allowaccess <protocols>
end

See Also

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/612504/hardening-your-fortigate

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: FortiGate

Control ID: 03e21a64e798c11d1c7c0e98003cf5960fa985a445fd1a6ca8309e7af4eb85a1