STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must have only one local account to be used as the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-234165r1051115_rule

Vulnerability Number

V-234165

Group Title

SRG-APP-000148-NDM-000346

Rule Version

FGFW-ND-000030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Administrators.
3. Review list of administrators and determine if any besides admin have Type listed as Local
4. For any with type Local, click Administrator, and then click Edit to change to remote authentication, or Delete to remove the administrator
5. To change the administrator to remote authentication, in Type select "Match a user on a remote server group".
6. In Remote User Group, select the appropriate configured remote user group.
7. Click OK.
8. Repeat for all administrators, besides admin that have local authentication listed.
9. Click OK.

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Administrators.
3. Verify the admin account is the only account configured as Type Local.

If more than one local user account exists, this is a finding.

Vulnerability Number

V-234165

Documentable

False

Rule Version

FGFW-ND-000030

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Administrators.
3. Verify the admin account is the only account configured as Type Local.

If more than one local user account exists, this is a finding.

Check Content Reference

M

Target Key

5260