STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

The FortiGate firewall must employ filters that prevent or limit the effects of all types of commonly known denial-of-service (DoS) attacks, including flooding, packet sweeps, and unauthorized port scanning.

DISA Rule

SV-234151r852961_rule

Vulnerability Number

V-234151

Group Title

SRG-NET-000362-FW-000028

Rule Version

FNFG-FW-000110

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Policy and Objects.
2. Click IPv4 DoS Policy or IPv6 DoS Policy.
3. Click +Create New.
4. Configure DoS policies that include Incoming Interface, Source Address, Destination Address, and Services.
5. Configure Action and Threshold for L3 and L4 anomalies per site policies.
6. Click OK.

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Policy and Objects.
2. Click IPv4 DoS Policy.
3. Verify different DoS policies that include Incoming Interface, Source Address, Destination Address, and Services have been created.
4. Double-.click on each policy.
5. Verify the DS policies are configured with appropriate thresholds for L3 and L4 anomalies.

If the DoS policies are not configured to filter packets associated with flooding, packet sweeps, and unauthorized port scanning, this is a finding.

Vulnerability Number

V-234151

Documentable

False

Rule Version

FNFG-FW-000110

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Policy and Objects.
2. Click IPv4 DoS Policy.
3. Verify different DoS policies that include Incoming Interface, Source Address, Destination Address, and Services have been created.
4. Double-.click on each policy.
5. Verify the DS policies are configured with appropriate thresholds for L3 and L4 anomalies.

If the DoS policies are not configured to filter packets associated with flooding, packet sweeps, and unauthorized port scanning, this is a finding.

Check Content Reference

M

Target Key

5258