FortiGate hardening is not one setting that can be switched on. It is the combined result of administrative access, authentication, interfaces, services, VPNs, logging, policy, objects, and operational discipline.
The most serious gaps are often simple settings that were enabled for convenience and then forgotten.
Common management-plane weaknesses
- HTTP, HTTPS, SSH, Telnet, SNMP, or FGFM exposed on unnecessary interfaces
- Trusted hosts missing or too broad
- Shared or unused administrator accounts
- MFA not used where the deployment supports it
- Local-in protection missing or incomplete
- Old certificates or insecure management choices
Common policy and inspection gaps
- Any/Any/Any or oversized service rules
- Internet-facing policy without the expected inspection profiles
- Disabled or incomplete logging
- Shadowed and duplicate rules
- Unclear policy comments and ownership
- Broad VPN access or weak authentication methods
Operational settings matter too
Backups, firmware planning, certificate lifecycle, HA, audit logging, denied-traffic visibility, and configuration-change review all affect how safely the firewall can be operated.
Use a repeatable baseline
A written standard is useful, but the review should also test the live configuration. Structured checks reduce the chance that a busy engineer will miss a setting buried elsewhere in the CLI.
Next step: run a configsentry audit and use the findings as a practical hardening list rather than trying to inspect every configuration section from memory.