STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

The FortiGate firewall must filter traffic destined to the internal enclave in accordance with the specific traffic that is approved and registered in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL), Vulnerability Assessments (VAs) for that the enclave.

DISA Rule

SV-234147r628789_rule

Vulnerability Number

V-234147

Group Title

SRG-NET-000205-FW-000040

Rule Version

FNFG-FW-000085

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.
1. Click Policy and Objects.
2. Click IPv4 or IPv6 Policy.
3. Click +Create New.
4. Name the policy, select Incoming and Outgoing Interfaces.
5. Create policies with authorized sources and destinations.
6. Set action to ACCEPT.
7. Ensure the Enable this policy is toggled to right.
8. Click OK.
9. Ensure a policy is created for each interface.

Traffic is denied by default and policies must be configured to allow traffic that meets PPSM CAL and VA guidelines.

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show firewall policy
# show firewall policy6

Ensure policies are created that only allow approved traffic that is in accordance with the PPSM CAL and VAs for the enclave.

If configured policies allow traffic that is not allowed per the PPSM CAL and VAs for the enclave, this is a finding.

Vulnerability Number

V-234147

Documentable

False

Rule Version

FNFG-FW-000085

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show firewall policy
# show firewall policy6

Ensure policies are created that only allow approved traffic that is in accordance with the PPSM CAL and VAs for the enclave.

If configured policies allow traffic that is not allowed per the PPSM CAL and VAs for the enclave, this is a finding.

Check Content Reference

M

Target Key

5258