Fortigate - Close port TCP 113 on external interface

Information

You can use the config system interface command to disable unused protocols that attackers may attempt to use to gather information about a FortiGate unit. Many of these protocols are disabled by default. Using the config system interface command you can see the current configuration of each of these options for the selected interface and then choose to disable them if required.

Solution

To disable the port on the wan1 interface, use the following CLI command:

config system interface
edit wan1
set ident-accept disable
end

See Also

https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/612504/hardening-your-fortigate

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: FortiGate

Control ID: fcbc2c4d41b5353223a67b6d487bf8f2c5a3f606be680d8ec2649b5efbddbbf7