FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
amatos
Staff & Editor
Staff & Editor
Article Id 357971
Description This article describes a behavior change since v7.0.16/v7.2.11/v7.4.6/v7.6.1, where now the Security Level information uses the low/high attributes instead of 0/1/2.
Scope FortiGate.
Solution

Since firmware v7.0.16/v7.2.11/v7.4.6/v7.6.1, the Security Level naming has changed from the common 0, 1, and 2 levels low, and high.

In the v7.0.15 and other versions it would be seen the below information by using the following command: 

 

get system status

 

When set as Security Level 0 in the boot menu:

 

FortiGate-60F # get sys status
Version: FortiGate-60F v7.0.15,build0632,240401 (GA.M)
Security Level: 0
Firmware Signature: certified

 

When set as Security Level 1 in the boot menu:

 

FortiGate-60F # get sys status
Version: FortiGate-60F v7.0.15,build0632,240401 (GA.M)
Security Level: 1
Firmware Signature: certified

 

When set as Security Level 2 in the boot menu:

 

FortiGate-60F # get sys status
Version: FortiGate-60F v7.0.15,build0632,240401 (GA.M)
Security Level: 2
Firmware Signature: certified

 

In v7.0.16, the naming of the level has changed as below:

 

When set as Security Level 0 in the boot menu:

 

FortiGate-60F # get sys status
Version: FortiGate-60F v7.0.16,build0667,241001 (GA.M)
Security Level: Low
Firmware Signature: certified

 

When set as Security Level 1 in the boot menu:

 

FortiGate-60F # get sys status
Version: FortiGate-60F v7.0.16,build0667,241001 (GA.M)
Security Level: Low
Firmware Signature: certified

 

When set as Security Level 2 in the boot menu:

 

FortiGate-60F # get system status
Version: FortiGate-60F v7.0.16,build0667,241001 (GA.M)
Security Level: High
Firmware Signature: certified

 

If the device is running firmware versions lower than 7.0.12/7.2.5/7.4.0 but it supports a BIOS version with the integrity checking enhancement, it is possible to check the current security level by interrupting the boot sequence as below:

 

  1. Connect to the unit via the console and reboot the firewall
  2. When 'Press any key to display configuration menu...' is displayed, interrupt the boot sequence.
  3. After the following menu appears, press 'I' for 'System configuration and information':

 

[C]: Configure TFTP parameters.
[R]: Review TFTP parameters.
[T]: Initiate TFTP firmware transfer.
[F]: Format boot device.
[B]: Boot with backup firmware and set as default.
[I]: System configuration and information.
[Q]: Quit menu and continue to boot.
[H]: Display this list of options.

 

 

  1. A new menu will appear. Select 'U' for 'Set security level':

 

[S]: Set serial port baudrate (will take effect on next boot).
[R]: Set restricted mode.
[T]: Set menu timeout.
[U]: Set security level.
[I]: Display system information.
[E]: Reset system configuration.
[M]: Enter memory test menu.
[Q]: Quit this menu.
[H]: Display this list of options.

 

  1. The new menu will display the current value:

 

Please select security level: [1] <----- Current value is set to level 1.
[0]: Level 0
[1]: Level 1
[2]: Level 2
Enter selection:

 

 

For more information about the change, see BIOS security Low and High level classification.