SV-234146r611438_rule
V-234146
SRG-NET-000193-FW-000030
FNFG-FW-000075
CAT II
10
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click Policy and Objects.
2. Click IPv4 DoS Policy or IPv6 DoS Policy.
3. Click +Create New.
4. Select the Incoming Interface.
5. Select Source and Destination addresses.
6. Select the Service.
7. Enable desired L3 and L4 anomalies and thresholds.
8. Ensure the Enable this policy is toggle to right.
9. Click OK.
10. Ensure a policy is created for each interface where there is potential risk of DoS.
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click Policy and Objects.
2. Go to IPv4 DoS Policy.
3. Verify different DoS policies that include Incoming Interface, Source Address, Destination Address, and Services have been created.
4. Verify the DoS policies are configured to block L3 and L4 anomalies.
If the DoS policies are not configured to block excess traffic, this is a finding.
V-234146
False
FNFG-FW-000075
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click Policy and Objects.
2. Go to IPv4 DoS Policy.
3. Verify different DoS policies that include Incoming Interface, Source Address, Destination Address, and Services have been created.
4. Verify the DoS policies are configured to block L3 and L4 anomalies.
If the DoS policies are not configured to block excess traffic, this is a finding.
M
5258