FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Gab_FTNT
Staff & Editor
Staff & Editor
Article Id 394045

 

Description This article describes how to change the security level on a G series FortiGate.
Scope FortiGate G series.
Solution BIOS Security Level can be changed from CLI on the other FortiGate hardware models: BIOS-level signature and file integrity

On FortiGate G series, a physical switch button in front or behind the device can be found to switch from Low to High:
  • High: Unsigned firmware blocked (default).
  • Low: Unsigned firmware allowed with a warning.


201G.jpg
Some FortiGate G series will have 3 different BIOS Security levels, such as level 0,1, or 2. Refer to this document to see the difference between those levels: Enhance BIOS-level signature and file integrity checking

The lights on the front panel will show the current security level in operation, as shown in this example.

Example1.png

 

There is also a FortiGate G series model that only shows the security level light on the Front panel, but the control switch is set in the back panel as per 71G in the following example.

Media (3).jpg

The next step to change the security level is to reboot the device and break the booting sequence. The picture below shows the set of actions that are supposed to be taken so the security level can be changed. These are the steps to be chosen from the boot menu:

  1. I: System configuration and information
  2. R: Restricted mode
  3. 2: Disable restricted mode.

 

restricted2.jpg

 

The result should be as in the 'get system status' output below. The important outputs are on the lines 'Current Security Level' and 'Physical Switch Security Level'. Once these parameters are 'low', the parameters of the FortiGate are successfully changed and ready for the needed operations (for example, installing an interim build). 

 

200g get system status.png

 

For more details on where the controlled BIOS security level switch is located.


Refer to the following site and search for the model number. The information can be found within the Datasheet: FortiGate Hardware Guide