STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must require that when a password is changed, the characters are changed in at least eight of the positions within the password.

DISA Rule

SV-234221r1153456_rule

Vulnerability Number

V-234221

Group Title

SRG-APP-000170-NDM-000329

Rule Version

FGFW-ND-000311

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# config system password-policy
# set change-8-characters enable
# end

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show full-configuration system password-policy | grep -i change
The output should be:
# set change-8-characters enable

If the change-8-characters parameter is set to disable, this is a finding.

Vulnerability Number

V-234221

Documentable

False

Rule Version

FGFW-ND-000311

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# show full-configuration system password-policy | grep -i change
The output should be:
# set change-8-characters enable

If the change-8-characters parameter is set to disable, this is a finding.

Check Content Reference

M

Target Key

5260