Skip to content
Security & DefenderChecklist

FortiGate Hardening Checklist for Small Businesses

A practical review of a small-business FortiGate. Firmware, admin access, VPN, firewall policies, logging, and backups. Interactive checklist, and your progress is saved in your browser.

Internet-facing firewalls and VPN appliances are one of the most common ways ransomware gets in. FortiGates are excellent firewalls, but a unit that was set up once and never revisited usually has at least a few of the gaps below. Work through this list with an admin login and a recent config backup in hand. Click an item to check it off, and your progress is saved in this browser.

Firmware

  • FortiOS is on a currently supported release, ideally the version Fortinet marks as recommended for your model
  • You've checked Fortinet PSIRT advisories for your version, especially anything affecting VPN or the admin interface
  • There's a process for applying critical firmware updates within days, not months

Administrative access

  • The admin interface (HTTPS/SSH) is not reachable from the internet on WAN interfaces
  • Trusted hosts are set on every admin account, restricting where admins can log in from
  • HTTP and Telnet admin access are disabled everywhere
  • The default admin account is renamed or disabled, and each person has a named account
  • Admin accounts use MFA (FortiToken or another supported method)
  • Admin profiles follow least privilege. Not everyone needs super_admin.
  • Login lockout and a strong password policy are configured

VPN and remote access

  • Remote access VPN requires MFA
  • You have a plan for Fortinet's move away from SSL VPN toward IPsec (or ZTNA). Check what your firmware version still supports.
  • VPN users are in groups with access only to what they need, not "all internal"
  • Unused VPN portals, tunnels, and local test accounts are removed

Firewall policies

  • No any-to-any allow policies between WAN and internal networks
  • Inbound port forwards (VIPs) are documented, needed, and restricted by source where possible
  • Unused policies (zero hit count for months) are reviewed and removed
  • Security profiles (IPS, antivirus, web filtering, application control) are applied to internet-bound traffic
  • Geo-blocking limits inbound traffic from countries you don't do business with
  • Local-in policies restrict what can reach the firewall itself

Services and interfaces

  • Unused interfaces are disabled
  • Management protocols like SNMP are v3 only, or off
  • FortiGuard subscriptions and signature updates are current

Logging and backup

  • Logs go somewhere they'll survive (FortiAnalyzer, FortiGate Cloud, or a syslog server)
  • Admin logins and config changes trigger alerts
  • NTP is configured so log timestamps are accurate
  • Automatic configuration backups are stored off the device, and one has been tested
  • The firewall's support contract and license renewal dates are on someone's calendar

Afterwards

Document what you changed and why. The next person to touch the firewall, or your insurer, will ask.

// Newsletter

New runbooks, straight to your inbox.

One email when something worth reading ships. No spam, unsubscribe anytime.