What AuditXA Checks on FortiGate
25+ security controls checked across every major FortiOS hardening category.
Admin Access Hardening
Checks for admin interface exposed on WAN, default account names, weak password policy, missing MFA, trusted host restrictions and session timeouts.
SSL Inspection
Verifies deep SSL/TLS inspection is configured on outbound policies. Over 85% of malware uses encrypted channels โ uninspected HTTPS is a critical gap.
Firewall Policy Review
Flags overly permissive rules (any/any), unused policies, rules without logging, missing application control and missing IPS profiles.
Logging & Monitoring
Checks FortiAnalyzer/syslog configuration, log levels, disk logging settings and whether denied traffic is being logged for incident response.
VPN Configuration
Reviews IPsec and SSL VPN settings for weak encryption, missing DPD, default pre-shared keys, split tunnelling policy and two-factor enforcement.
System Hardening
Checks SNMP community strings, NTP configuration, DNS over TLS, firmware version, unused services disabled and management VLAN isolation.
Sample Findings
These are real finding types from FortiGate audits. Severity, description and exact CLI fix included for every issue.
Current config:
set allowaccess ping
Fix:
set ssl-ssh-profile "deep-inspection"
Fix:
Run Your FortiGate Audit Now
Upload your config file โ results in under 60 seconds. Config never stored or transmitted.
๐ Start Free Audit