STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must generate audit records for privileged activities or other system-level access.

DISA Rule

SV-234175r961827_rule

Vulnerability Number

V-234175

Group Title

SRG-APP-000504-NDM-000321

Rule Version

FGFW-ND-000080

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

When Event Logging is enabled, the device will audit privileged activities or other system-level access. To enable event logging, log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:

# config log eventfilter
# set event enable
# set system enable
# end

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show full-configuration log eventfilter | grep -i 'event\|system'

The output should be:
set event enable
set system enable

If the event and system parameters are set to disable, this is a finding.

Vulnerability Number

V-234175

Documentable

False

Rule Version

FGFW-ND-000080

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show full-configuration log eventfilter | grep -i 'event\|system'

The output should be:
set event enable
set system enable

If the event and system parameters are set to disable, this is a finding.

Check Content Reference

M

Target Key

5260