STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

The FortiGate firewall must protect the traffic log from unauthorized deletion of local log files and log records.

DISA Rule

SV-234143r611429_rule

Vulnerability Number

V-234143

Group Title

SRG-NET-000100-FW-000023

Rule Version

FNFG-FW-000060

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Admin Profiles.
3. Click +Create New (Admin Profile).
4. Assign a meaningful name to the Profile.
5. Set Log and Report access permissions to None.
6. Click OK to save this Profile.

Then,
1. Click System.
2. Click Administrators.
3. Click the Administrator that is not allowed access to log settings.
4. Assign the Admin Profile that was created above.
5. Click OK to save.

Repeat this process to remove log access for all Administrators without an organizational need to modify log records.

Check Contents

Log in to the FortiGate GUI with an administrator that has no Log and Report access.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
$ execute log delete

3. Ensure that the command fails.

If an Administrator without Log and Report privileges can delete locally stored logs, this is a finding.

Vulnerability Number

V-234143

Documentable

False

Rule Version

FNFG-FW-000060

Severity Override Guidance

Log in to the FortiGate GUI with an administrator that has no Log and Report access.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
$ execute log delete

3. Ensure that the command fails.

If an Administrator without Log and Report privileges can delete locally stored logs, this is a finding.

Check Content Reference

M

Target Key

5258