4.3.3 Apply DNS Filter Security Profile to Policies

Information

Ensuring that traffic traversing to the Internet on the FortiGate has a DNS Filter security profile inspecting it.

Rationale:

Traffic outbound to the Internet on the FortiGate should have firewall policies applied with an DNS Filter security profile applied.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure on 'Allowed' firewall policies that handle traffic outbound to Internet to have an appropriate DNS Filter security profile applied to policies.

Default Value:

Not Configured

See Also

https://workbench.cisecurity.org/benchmarks/12961

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3

Plugin: FortiGate

Control ID: 6146864cfa5c8e1dd09bf708aa7ddd0edc4e50dd2e5ae0a7dce6b60ada363349