Fortigate - Review and disable unused interfaces

Information

Review and disable unused interfaces. Disabling unused interfaces reduces the attack surface of the device.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

If any of the interfaces on the FortiGate unit are not being used, disable traffic on that interface. This avoids someone plugging in network cables and potentially causing network bypass or loop issues.

To disable an interface - web-based manager
1 Go to System > Network > Interface.
2 Select the interface from the list and select Edit.
3 For Administrative Access, select Down.
4 Select OK.

To disable an interface - CLI

config system interface
edit <inerface_name>
set status down
end

See Also

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/612504/hardening-your-fortigate

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-7b., 800-53|SC-41, CSCv6|9.1

Plugin: FortiGate

Control ID: b5ba41b51f512d607f544aa6db3bdf60fe1ef4b837f4d94b37b55960aff44b42