4.4.3 Ensure all Application Control related traffic is logged

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Ensure no category is set to "Allow" on FortiGate Application Control.

Any category that is set as "Allow" on Application Control will not be logged. This creates a visibility gap on security investigation. This includes "Unknown Applications" category.

Solution

On GUI:

1. Go to "Security Profiles" > "Application Control".
2. Select the relevant App Control profile.
3. Change any categories with "Allow" action to "Monitor".

Impact:

Visibility gap, which affects incident forensics and response.

See Also

https://workbench.cisecurity.org/benchmarks/15284