SV-234145r611435_rule
V-234145
SRG-NET-000192-FW-000029
FNFG-FW-000070
CAT II
10
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click Policy and Objects.
2. Click IPv4 DoS Policy or IPv6 DoS Policy.
3. Click +Create New.
4. Select the Incoming Interface.
5. Select Source and Destination addresses.
6. Select the Service.
7. Enable desired L3 and L4 anomalies and thresholds.
8. Ensure the Enable this policy is toggled to right.
9. Click OK.
10. Ensure a policy is created for each interface where there is potential risk of DoS.
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click Policy and Objects.
2. Go to IPv4 DoS Policy.
3. Verify different DoS policies that include Incoming Interface, Source Address, Destination Address, and Services have been created.
4. Verify the DoS policies are configured to block L3 and L4 anomalies.
If the DoS policies are not configured to block the outbound traffic, this is a finding.
V-234145
False
FNFG-FW-000070
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click Policy and Objects.
2. Go to IPv4 DoS Policy.
3. Verify different DoS policies that include Incoming Interface, Source Address, Destination Address, and Services have been created.
4. Verify the DoS policies are configured to block L3 and L4 anomalies.
If the DoS policies are not configured to block the outbound traffic, this is a finding.
M
5258