SV-234143r611429_rule
V-234143
SRG-NET-000100-FW-000023
FNFG-FW-000060
CAT I
10
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click System.
2. Click Admin Profiles.
3. Click +Create New (Admin Profile).
4. Assign a meaningful name to the Profile.
5. Set Log and Report access permissions to None.
6. Click OK to save this Profile.
Then,
1. Click System.
2. Click Administrators.
3. Click the Administrator that is not allowed access to log settings.
4. Assign the Admin Profile that was created above.
5. Click OK to save.
Repeat this process to remove log access for all Administrators without an organizational need to modify log records.
Log in to the FortiGate GUI with an administrator that has no Log and Report access.
1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
$ execute log delete
3. Ensure that the command fails.
If an Administrator without Log and Report privileges can delete locally stored logs, this is a finding.
V-234143
False
FNFG-FW-000060
Log in to the FortiGate GUI with an administrator that has no Log and Report access.
1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
$ execute log delete
3. Ensure that the command fails.
If an Administrator without Log and Report privileges can delete locally stored logs, this is a finding.
M
5258