Technical Tip: Predefined security profiles, profile group, and firewall policies created after enabling FIPS-CC mode
| Description | This article describes why predefined FIPS-CC UTM profiles, a profile group, and policies are automatically created after enabling FIPS-CC mode. |
| Scope | FortiOS. |
| Solution | After enabling FIPS-CC mode (see Technical Tip: How to enable FIPS-CC mode), the FortiGate automatically creates a 'FIPS-CC' UTM profile for each security profile, except for Video Filter, File Filter, Virtual Patching, and CASB.
In addition, FortiOS generates a profile group named 'FIPS-CC', which references all the individual FIPS-CC security profiles created.
By default, the profile group is hidden in the GUI. To display it, run the following commands:
config system settings set gui-security-profile-group enable end Furthermore, the FortiGate automatically creates six policies with the action set to 'Deny', as shown below:
Related articles:
|

