SV-234147r628789_rule
V-234147
SRG-NET-000205-FW-000040
FNFG-FW-000085
CAT II
10
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click Policy and Objects.
2. Click IPv4 or IPv6 Policy.
3. Click +Create New.
4. Name the policy, select Incoming and Outgoing Interfaces.
5. Create policies with authorized sources and destinations.
6. Set action to ACCEPT.
7. Ensure the Enable this policy is toggled to right.
8. Click OK.
9. Ensure a policy is created for each interface.
Traffic is denied by default and policies must be configured to allow traffic that meets PPSM CAL and VA guidelines.
Log in to the FortiGate GUI with Super-Admin privilege.
1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show firewall policy
# show firewall policy6
Ensure policies are created that only allow approved traffic that is in accordance with the PPSM CAL and VAs for the enclave.
If configured policies allow traffic that is not allowed per the PPSM CAL and VAs for the enclave, this is a finding.
V-234147
False
FNFG-FW-000085
Log in to the FortiGate GUI with Super-Admin privilege.
1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show firewall policy
# show firewall policy6
Ensure policies are created that only allow approved traffic that is in accordance with the PPSM CAL and VAs for the enclave.
If configured policies allow traffic that is not allowed per the PPSM CAL and VAs for the enclave, this is a finding.
M
5258