STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

The FortiGate firewall must block outbound traffic containing denial-of-service (DoS) attacks to protect against the use of internal information systems to launch any DoS attacks against other networks or endpoints.

DISA Rule

SV-234145r611435_rule

Vulnerability Number

V-234145

Group Title

SRG-NET-000192-FW-000029

Rule Version

FNFG-FW-000070

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Policy and Objects.
2. Click IPv4 DoS Policy or IPv6 DoS Policy.
3. Click +Create New.
4. Select the Incoming Interface.
5. Select Source and Destination addresses.
6. Select the Service.
7. Enable desired L3 and L4 anomalies and thresholds.
8. Ensure the Enable this policy is toggled to right.
9. Click OK.
10. Ensure a policy is created for each interface where there is potential risk of DoS.

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Policy and Objects.
2. Go to IPv4 DoS Policy.
3. Verify different DoS policies that include Incoming Interface, Source Address, Destination Address, and Services have been created.
4. Verify the DoS policies are configured to block L3 and L4 anomalies.

If the DoS policies are not configured to block the outbound traffic, this is a finding.

Vulnerability Number

V-234145

Documentable

False

Rule Version

FNFG-FW-000070

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Policy and Objects.
2. Go to IPv4 DoS Policy.
3. Verify different DoS policies that include Incoming Interface, Source Address, Destination Address, and Services have been created.
4. Verify the DoS policies are configured to block L3 and L4 anomalies.

If the DoS policies are not configured to block the outbound traffic, this is a finding.

Check Content Reference

M

Target Key

5258