Compliance
Bibliothèque de règles intégrées + éditeur pour règles custom
| ID | Nom | Sévérité | Catégorie | Framework | Activé |
|---|---|---|---|---|---|
SEC-001 | Allow any-to-any rules | critical | security | Built-in | actif |
SEC-002 | Dangerous service exposure | high | security | Built-in | actif |
SEC-003 | Deny rules without logging | medium | security | Built-in | actif |
SEC-004 | Cleartext management | high | security | Built-in | actif |
SEC-005 | No geo-blocking | low | security | Built-in | actif |
HYG-001 | Duplicate address objects | low | hygiene | Built-in | actif |
HYG-002 | Orphan objects | info | hygiene | Built-in | actif |
HYG-003 | Shadowed rules | high | hygiene | Built-in | actif |
OPT-001 | Consolidation candidates | info | optimization | Built-in | actif |
COMP-CIS-3.1 | Explicit deny-all required | medium | compliance | CIS FortiGate | actif |
COMP-CIS-3.2 | Allow rules must log | low | compliance | CIS FortiGate | actif |