Summary: Any-any rules, management exposed on WAN, VPN without MFA, outdated FortiOS: common findings in FortiGate configuration audits and how to fix them.

A firewall is usually tidy on the day it is installed. Problems build up over time: a temporary rule opened for an urgent request, the account of an employee who has left, a postponed firmware update. That is why the configuration needs to be read end to end at regular intervals.

Below are findings that come up often in FortiGate configuration audits, with a practical fix for each.

1. Any-any allow rules

Rules whose source, destination and service are all set to "all" effectively remove segmentation. Narrow them down to the real traffic; the rule hit count helps you see what actually passes.

2. Unused and shadowed rules

Rules that never receive traffic, or never match because a broader rule above them catches it first, make the rule set hard to read. Disable them for a while and watch the impact before deleting.

3. Management access open on the WAN interface

HTTPS, SSH or ping management access on the internet-facing side is direct attack surface. Restrict management to the internal network or VPN and define trusted hosts for administrator accounts.

4. Remote access without MFA

If SSL or IPsec VPN users sign in with a password only, a single leaked password means access to the internal network. Add multi-factor authentication for every VPN user.

5. Outdated FortiOS and known vulnerabilities

Compare the FortiOS version running on the device with the vendor's security advisories on a regular basis. End-of-life versions no longer receive patches.

6. Logs not sent off the device

Logs kept only on the device fill up quickly, and after an incident there is nothing to look back at. Define a syslog, SIEM or FortiAnalyzer target and plan the retention period around your legal obligations.

7. Weak administrator account hygiene

A shared admin account, active accounts of former employees and a weak password policy are frequent findings. Use personal accounts, least-privilege profiles and regular account reviews.

8. No backups or change log

If config backups are not taken, or nobody knows who made which change, rolling back after a mistake can take hours. Take a backup after every change and keep the versions.

Practical tip

Audit at least quarterly, not once a year. In each round, sort findings by severity and close the critical ones first. Small, regular improvements are more sustainable than one big clean-up project.

Making audits routine

Denetta audits the FortiGate configuration read-only, without writing to any device. It produces findings from 126 rules, matches the FortiOS version against known vulnerabilities and combines the results into a 0-100 Infrastructure Health Score. You can start with a single FortiGate backup file and no installation; licences start at $19 per site per month.

See your firewall's health score

The first Denetta report is free. Let's agree on the scope in an intro call.

Request an intro call