STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

The FortiGate firewall must allow authorized users to record a packet-capture-based IP, traffic type (TCP, UDP, or ICMP), or protocol.

DISA Rule

SV-234159r982101_rule

Vulnerability Number

V-234159

Group Title

SRG-NET-000399-FW-000008

Rule Version

FNFG-FW-000155

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

Create a Packet Capture Filter
1. Click Network.
2. Click Packet Capture.
3. Click +Create New.
4. Select an interface from the drop down menu.
5. Specify the maximum number of packets to capture.
6. Enable Filters to configure filtering based upon Host (addresses), Port, VLAN, or Protocol.
7. Click OK.

Then,
1. Select a packet filter from the list of packet capture filters.
2. Right-click on the selected filter.
3. Click Start.
4. Click OK.
The packet capture continues until either the configured number of packets is reached, or the administrator stops the packet capture. The administrator must download the packet capture for viewing with an external application, like Wireshark or tcpdump.

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Network.
2. Click Packet Capture.
3. Verify different Packet Capture Filters are configured and that capture packets based on interface, host, VLAN, or protocol.

If FortiGate does not allow an authorized administrator to capture packets based on interface, host, VLAN, or protocol, this is a finding.

Vulnerability Number

V-234159

Documentable

False

Rule Version

FNFG-FW-000155

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Network.
2. Click Packet Capture.
3. Verify different Packet Capture Filters are configured and that capture packets based on interface, host, VLAN, or protocol.

If FortiGate does not allow an authorized administrator to capture packets based on interface, host, VLAN, or protocol, this is a finding.

Check Content Reference

M

Target Key

5258