Skip to main content
syao
Staff & Editor
Staff & Editor
March 5, 2026

Technical Tip: Predefined security profiles, profile group, and firewall policies created after enabling FIPS-CC mode

  • March 5, 2026
  • 0 replies
  • 171 views
Description This article describes why predefined FIPS-CC UTM profiles, a profile group, and policies are automatically created after enabling FIPS-CC mode.
Scope FortiOS.
Solution

After enabling FIPS-CC mode (see Technical Tip: How to enable FIPS-CC mode), the FortiGate automatically creates a 'FIPS-CC' UTM profile for each security profile, except for Video FilterFile Filter, Virtual Patching, and CASB.

 

In addition, FortiOS generates a profile group named 'FIPS-CC', which references all the individual FIPS-CC security profiles created.

 

profile-group.png

 

By default, the profile group is hidden in the GUI. To display it, run the following commands:

 

config system settings
    set gui-security-profile-group enable
end
 

Furthermore, the FortiGate automatically creates six policies with the action set to 'Deny', as shown below:

 

security policy.png

 

Related articles: