4.1.1 Detect Botnet connections

Information

Interfaces which are classified as \\"WAN\\" and are used by a policy should use an IPS sensor which blocks or monitors outgoing connections to botnet sites.

Blocking outgoing connections to known Botnets should be utilized in a Defense In Depth network design.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

On GUI:

1. Configure relevant IPS profiles with \\"Scan Outgoing Connections to Botnet Sites\\" set to \\"Block\\".
2. Apply relevant IPS profile on all firewall policies with traffic exiting the network to a \\"WAN\\" interface.

See Also

https://workbench.cisecurity.org/benchmarks/24708

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, 800-53|SI-4(4), CSCv7|12.7, CSCv7|15.3

Plugin: FortiGate

Control ID: 80373a7a0a1229f549e17c90d75b86d1ac50b13d0e9629c8a831122f78533a50