STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

The FortiGate firewall must protect the traffic log from unauthorized modification of local log records.

DISA Rule

SV-234142r611426_rule

Vulnerability Number

V-234142

Group Title

SRG-NET-000099-FW-000161

Rule Version

FNFG-FW-000055

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Admin Profiles.
3. Click +Create New (Admin Profile).
4. Assign a meaningful name to the Profile.
5. Set Log and Report access permissions to None.
6. Click OK to save this Profile.

Then,
1. Click System.
2. Click Administrators.
3. Click the Administrator that is not allowed access to log records.
4. Assign the Admin Profile that was created above.
5. Click OK to save.

Repeat this process to remove log access for all Administrators without an organizational need to modify log settings.

Check Contents

Log in to the FortiGate GUI with an administrator that has no Log and Report access.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
$ config log setting

3. Ensure that the command fails.

If an Administrator without Log and Report privileges can configure log settings, this is a finding.

Vulnerability Number

V-234142

Documentable

False

Rule Version

FNFG-FW-000055

Severity Override Guidance

Log in to the FortiGate GUI with an administrator that has no Log and Report access.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
$ config log setting

3. Ensure that the command fails.

If an Administrator without Log and Report privileges can configure log settings, this is a finding.

Check Content Reference

M

Target Key

5258