STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.

DISA Rule

SV-234217r961620_rule

Vulnerability Number

V-234217

Group Title

SRG-APP-000435-NDM-000315

Rule Version

FGFW-ND-000290

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Policy and Objects.
2. Click IPv4 DoS Policy or IPv6 DoS Policy.
3. Identify the port designated for FortiGate device management.
4. Click +Create New.
5. Define the Incoming Interface, Source Address, Destination Address, and Services.
6. Configure L3 Anomalies, and L4 Anomalies to meet the organization requirement.
7. Click OK.

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Policy and Objects.
2. Click on IPv4 DoS Policy or IPv6 DoS Policy.
3. Identify the port designated for FortiGate device management.
4. Select the policy and click Edit.
5. Verify appropriate L3 Anomalies and L4 Anomalies are configured to meet the organization requirement.
6. Verify the policy is Enabled.

If appropriate DoS policies are not defined or are disabled, this is a finding.

Vulnerability Number

V-234217

Documentable

False

Rule Version

FGFW-ND-000290

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Policy and Objects.
2. Click on IPv4 DoS Policy or IPv6 DoS Policy.
3. Identify the port designated for FortiGate device management.
4. Select the policy and click Edit.
5. Verify appropriate L3 Anomalies and L4 Anomalies are configured to meet the organization requirement.
6. Verify the policy is Enabled.

If appropriate DoS policies are not defined or are disabled, this is a finding.

Check Content Reference

M

Target Key

5260