Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
thuyavanavan
New Contributor

Need to understand the Benchmark on the Security Rating Score in FortiGate Firewall

Dear Team,

Need your support to Understand the Industry Benchmark on the Secure Rating Score on the Fortigate Firewall.

 

1 REPLY 1
atakannatak
Contributor II

Hi @thuyavanavan ,

 

The Security Rating feature on FortiGate firewalls is an essential tool, especially for enterprise or compliance-driven environments. It provides a comprehensive, automated assessment of your firewall's configuration, ensuring alignment with Fortinet best practices, NIST, PCI-DSS, and Zero Trust principles.

 

The key advantages of the Security Rating include its ability to identify misconfigurations, risky or unused policies, lack of SSL inspection or logging, weak admin practices, and inadequate interface hardening—issues that could introduce significant vulnerabilities if left unaddressed. Most importantly, it doesn’t simply highlight problems but also offers actionable remediation recommendations, which can drastically reduce attack surfaces and improve visibility.

 

One of the most critical aspects of the Security Rating is that it enables you to compare your FortiGate’s security posture against global standards and industry peers. This comparison helps you prioritize key actions, such as enforcing admin timeouts, blocking weak ciphers, enabling comprehensive UTM logging, and securing remote access.

 

The report not only helps prevent configuration drift over time but also serves as valuable evidence during audits or risk assessments. It's highly recommended to run these checks regularly and integrate the Security Rating score into your security KPIs. While the score itself is not mandatory, it is a best-practice tool that significantly enhances operational security hygiene. Ignoring it could result in missing critical, often subtle risks in your firewall's configuration.

 

BR.

 

If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.

 

CCIE #68781

Atakan Atak
Atakan Atak
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors