STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must generate audit records containing the full-text recording of privileged commands.

DISA Rule

SV-234179r960909_rule

Vulnerability Number

V-234179

Group Title

SRG-APP-000101-NDM-000231

Rule Version

FGFW-ND-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# config system global
# set cli-audit-log enable
# end

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show full-configuration system global | grep -i cli-audit
The output should be:
set cli-audit-log enable

If cli-audit-log is set to disable, this is a finding.

Vulnerability Number

V-234179

Documentable

False

Rule Version

FGFW-ND-000100

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show full-configuration system global | grep -i cli-audit
The output should be:
set cli-audit-log enable

If cli-audit-log is set to disable, this is a finding.

Check Content Reference

M

Target Key

5260