The FortiGate firewall must generate traffic log entries containing information to establish the network location where the events occurred. (2024)

The FortiGate firewall must generate traffic log entries containing information to establish the network location where the events occurred.


Overview

Finding ID Version Rule ID IA Controls Severity
V-234137 FNFG-FW-000030 SV-234137r628776_rule Medium
Description
Without establishing where events occurred, it is impossible to establish, correlate, and investigate the events leading up to an outage or attack.To compile an accurate risk assessment and provide forensic analysis, it is essential for security personnel to know where events occurred, such as network element components, modules, device identifiers, node names, and functionality. Associating information about where the event occurred within the network provides a means of investigating an attack, recognizing resource utilization or capacity thresholds, or identifying an improperly configured network element.
STIG Date
Fortinet FortiGate Firewall Security Technical Implementation Guide 2021-01-29

Details

Check Text ( C-37322r611409_chk )
Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Log and Report.
2. Click Forward Traffic, or Local Traffic.
3. Double-click on an Event to view Log Details.
4. Verify traffic log events contain source and destination IP addresses, and interfaces.

In addition to System log settings, verify that individual firewall policies are configured with most suitable Logging Options.

1. Click Policy and Objects.
2. Click IPv4 or IPv6 Policy.
3. Verify all Policy rules are configured with Logging Options set to log All Sessions (for most verbose logging).

If the traffic log events do not contain source and destination IP addresses, or interfaces, this is a finding.

Fix Text (F-37287r611410_fix)
This fix can be performed on the FortiGate GUI or on the CLI.
Log in to the FortiGate GUI with Super-Admin privilege.

1. Click Log and Report.
2. Click Log Settings.
3. Click All for the Event Logging and Local Traffic Log options (for most verbose logging), or Click Customize and choose granular logging options to meet organization needs.
4. Scroll to UUIDs in Traffic Log and toggle Policy and Address buttons to enable.
5. Click Apply.

In addition to these log settings, configure individual firewall policies with the most suitable Logging Options.

1. Click Policy and Objects.
2. Click IPv4 or IPv6 Policy.
3. For each policy, configure Logging Options to log All Sessions (for most verbose logging).
4. Confirm each created Policy is Enabled.
5. Click OK.

or

1. Open a CLI console, via SSH or available from the GUI.
2. Run the following command:
# config log eventfilter
# set event enable
# set system enable
# set endpoint enable
# set user enable
# set security-rating enable
# end
3. For each configured policy set the following:
# config firewall {policy|policy6}
# edit {policyid}
# set logtraffic enable
# end

The {} indicate the object is defined by the organization policy.

The FortiGate firewall must generate traffic log entries containing information to establish the network location where the events occurred. (2024)
Top Articles
Junior ISA pros and cons
How to Make an Offer on a House | SmartAsset.com
Victor Spizzirri Linkedin
Artem The Gambler
Truist Bank Near Here
Chicago Neighborhoods: Lincoln Square & Ravenswood - Chicago Moms
Ets Lake Fork Fishing Report
THE 10 BEST Women's Retreats in Germany for September 2024
Comcast Xfinity Outage in Kipton, Ohio
Fototour verlassener Fliegerhorst Schönwald [Lost Place Brandenburg]
Green Bay Press Gazette Obituary
Wfin Local News
Cinepacks.store
Call of Duty: NEXT Event Intel, How to Watch, and Tune In Rewards
[PDF] INFORMATION BROCHURE - Free Download PDF
Wordle auf Deutsch - Wordle mit Deutschen Wörtern Spielen
House Party 2023 Showtimes Near Marcus North Shore Cinema
Craigslist Southern Oregon Coast
Cbssports Rankings
Today Was A Good Day With Lyrics
Cincinnati Adult Search
Ivegore Machete Mutolation
Providence Medical Group-West Hills Primary Care
Weve Got You Surrounded Meme
Ontdek Pearson support voor digitaal testen en scoren
Mandy Rose - WWE News, Rumors, & Updates
The 15 Best Sites to Watch Movies for Free (Legally!)
Tire Plus Hunters Creek
27 Fantastic Things to do in Lynchburg, Virginia - Happy To Be Virginia
Obsidian Guard's Skullsplitter
Earthy Fuel Crossword
Autotrader Bmw X5
Sports Clips Flowood Ms
Workboy Kennel
Shaman's Path Puzzle
Smartfind Express Henrico
Newcardapply Com 21961
M3Gan Showtimes Near Cinemark North Hills And Xd
Colorado Parks And Wildlife Reissue List
Ticketmaster Lion King Chicago
Studentvue Columbia Heights
Thanksgiving Point Luminaria Promo Code
Ashoke K Maitra. Adviser to CMD's. Received Lifetime Achievement Award in HRD on LinkedIn: #hr #hrd #coaching #mentoring #career #jobs #mba #mbafreshers #sales…
Blackstone Launchpad Ucf
Craigslist Pets Plattsburgh Ny
Scarlet Maiden F95Zone
Myrtle Beach Craigs List
Woody Folsom Overflow Inventory
Canonnier Beachcomber Golf Resort & Spa (Pointe aux Canonniers): Alle Infos zum Hotel
Mlb Hitting Streak Record Holder Crossword Clue
Nkey rollover - Hitta bästa priset på Prisjakt
Craigslist Centre Alabama
Latest Posts
Article information

Author: Greg O'Connell

Last Updated:

Views: 5362

Rating: 4.1 / 5 (62 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Greg O'Connell

Birthday: 1992-01-10

Address: Suite 517 2436 Jefferey Pass, Shanitaside, UT 27519

Phone: +2614651609714

Job: Education Developer

Hobby: Cooking, Gambling, Pottery, Shooting, Baseball, Singing, Snowboarding

Introduction: My name is Greg O'Connell, I am a delightful, colorful, talented, kind, lively, modern, tender person who loves writing and wants to share my knowledge and understanding with you.