My observation:
Secure Boot is a general control intended for the configuration review of firewalls. We are using a customized image during firmware updates, which makes this option not mandatory. You can either provide this justification to close the finding or, if feasible, implement the control using the attached reference
https://docs.fortinet.com/document/fortigate/7.4.0/new-features/249947/enhance-bios-level-signature-...
What is the relevance of changing the security level to 1 and how we can do this?
Solved! Go to Solution.
Hi @robinh007 ,
FortiOS introduces an enhanced security framework focused on the BIOS and runtime integrity of FortiGate devices. The improvements aim to detect unauthorized changes and ensure trustworthiness at the firmware level. This includes:
Changing the security level to 1 increases the strictness of file and BIOS validation. Here's why it's important:
Why set the security level to 1 in the FortiGate BIOS configuration:
You can set the enhanced integrity checking level using CLI (console access only) but reboot required for this process.
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
CCIE #68781
Hi @robinh007 ,
FortiOS introduces an enhanced security framework focused on the BIOS and runtime integrity of FortiGate devices. The improvements aim to detect unauthorized changes and ensure trustworthiness at the firmware level. This includes:
Changing the security level to 1 increases the strictness of file and BIOS validation. Here's why it's important:
Why set the security level to 1 in the FortiGate BIOS configuration:
You can set the enhanced integrity checking level using CLI (console access only) but reboot required for this process.
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
CCIE #68781
User | Count |
---|---|
2428 | |
1303 | |
778 | |
556 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.