SV-234157r611471_rule
V-234157
SRG-NET-000364-FW-000042
FNFG-FW-000145
CAT II
10
This fix can be performed via the CLI of the FortiGate.
1. Open a CLI console via SSH or from the GUI.
2. Run the following commands:
# config system settings
# set asymroute disable
# set asymroute-icmp disable
# set asymroute6 disable
# set asymroute6-icmp disable
# end
The FortiGate has RPF enabled by default, but it can be disabled for IPv4, IPv4 ICMP, IPv6, and IPv6-ICMP with the "set asymroute enable" commands. Log in to the FortiGate CLI with Super-Admin privilege, and then run the command:
# get system settings | grep asymroute
Unless this device is intentionally setup for asymmetric routing, if any of the settings are set to "enable" this is a finding.
V-234157
False
FNFG-FW-000145
The FortiGate has RPF enabled by default, but it can be disabled for IPv4, IPv4 ICMP, IPv6, and IPv6-ICMP with the "set asymroute enable" commands. Log in to the FortiGate CLI with Super-Admin privilege, and then run the command:
# get system settings | grep asymroute
Unless this device is intentionally setup for asymmetric routing, if any of the settings are set to "enable" this is a finding.
M
5258