SV-234165r1051115_rule
V-234165
SRG-APP-000148-NDM-000346
FGFW-ND-000030
CAT II
10
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click System.
2. Click Administrators.
3. Review list of administrators and determine if any besides admin have Type listed as Local
4. For any with type Local, click Administrator, and then click Edit to change to remote authentication, or Delete to remove the administrator
5. To change the administrator to remote authentication, in Type select "Match a user on a remote server group".
6. In Remote User Group, select the appropriate configured remote user group.
7. Click OK.
8. Repeat for all administrators, besides admin that have local authentication listed.
9. Click OK.
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click System.
2. Click Administrators.
3. Verify the admin account is the only account configured as Type Local.
If more than one local user account exists, this is a finding.
V-234165
False
FGFW-ND-000030
Log in to the FortiGate GUI with Super-Admin privilege.
1. Click System.
2. Click Administrators.
3. Verify the admin account is the only account configured as Type Local.
If more than one local user account exists, this is a finding.
M
5260