STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must generate audit records containing information that establishes the identity of any individual or process associated with the event.

DISA Rule

SV-234178r960906_rule

Vulnerability Number

V-234178

Group Title

SRG-APP-000100-NDM-000230

Rule Version

FGFW-ND-000095

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following commands:
# config log setting
# set user-anonymize disable
# end

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following commands:
# show full-configuration log setting | grep -i anonymize
The output should be:
set user-anonymize disable

If the log setting user-anonymize is set to enable, this is a finding.

Vulnerability Number

V-234178

Documentable

False

Rule Version

FGFW-ND-000095

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following commands:
# show full-configuration log setting | grep -i anonymize
The output should be:
set user-anonymize disable

If the log setting user-anonymize is set to enable, this is a finding.

Check Content Reference

M

Target Key

5260