Configuration Management · FortiGate

Your FortiGate runs
on the box,
not on a checklist.

A FortiGate security audit verifies what the firewall actually enforces: the admin plane, the inspection profiles, VPN posture, and the policy set itself. CIS verifies a profile is attached. Retrievy verifies it is effective, then lets you simulate a flow through the live rule set before you change it. 45 Layer-7 deep-inspection checks across SSL, AV, IPS, AppControl, WebFilter, DNS, and DLP, a Policy X-Ray with the Domino Effect, a read-only change simulator, and a Hygiene Engine that finds the zombie rules nobody dares delete.

Retrievy FortiGate Policy X-Ray: risk-ranked policies and the Layer 7 traffic pipeline for a selected rule

Policy X-Ray. Every rule scored, its Layer 7 pipeline traced node by node.

The Blind Spot

Green dots lie.

The GUI shows a green dot next to "WebFilter Profile". The CIS report says "WebFilter is attached". And the user is still browsing to phishing pages, because the WebFilter profile in question allows the FortiGuard category "Newly Observed Domains", or the policy underneath it has SSL deep inspection disabled, or the FortiGuard subscription quietly expired three weeks ago.

Zombie rules accumulate. Default profiles linger. Certificate hygiene decays. SSL inspection has a single misconfigured exception that blinds half the rule set.

Retrievy reads the live device and tells you what's actually working.

01 — Easy to Deploy

SSH read-only.
Three minutes per device.

The FortiGate Collector

A thin collector. The platform does the work.

The collector connects to your FortiGate over a read-only SSH session, gathers the configuration, encrypts it, and ships it to the Retrievy platform. All analysis runs server-side. The host running the collector stays light, and your firewall is never written to.

  • ·Windows agent or Docker container. Same collector, same auth, same offline queue. Pick whichever fits your environment.
  • ·Read-only admin profile. No write privilege, no API tokens that grant write, no inbound on the firewall, no agent on the FortiGate itself.
  • ·Outbound HTTPS only. The collector sends data to Retrievy. No inbound exposure on the firewall or the host.
  • ·Encrypted credentials at rest. FortiGate SSH credentials sealed to the host. Tokens rotate automatically.
  • ·Snapshot and diff on every scan. Each scan captures a fresh config snapshot and compares it against the prior one, so the Drift Engine reports a real change as a single, accurate event.
  • ·Add a second device in 30 seconds. Same credentials profile reused. Add an entire fleet in an afternoon.
Comparison

vs. FortiManager

FortiManager shows you the intended configuration. Retrievy reads the live device. When the two diverge, Retrievy flags it.

HA Clusters

Cluster-aware.

Reads from the active member. Cluster sync state surfaced in the dashboard. Drift between members is flagged before failover surprises you.

02 — Easy to Triage

Eight engines,
the whole device.

L7 Efficacy Engine

45 deep-inspection checks.

Eight UTM domains. Beyond CIS checkbox compliance.

DEPTH OF EFFICACY CHECKS PER UTM DOMAIN SSL/TLS 6 checks Antivirus 8 checks IPS 6 checks AppControl 6 checks WebFilter 8 checks DNS 4 checks DLP 4 checks Policy 3 checks TOTAL · 45 EFFICACY CHECKS

Audits whether the profile is actually doing its job: SSL depth, AV outbreak prevention, IPS critical-severity actions, AppControl unknown-traffic handling, WebFilter FTGD coverage, DNS botnet blocking, DLP PII detection.

Admin Plane · 28 CIS checks

The control plane, audited.

Admin password policy, idle timeout, trusted hosts, encrypted access only, pre/post-login banners, NTP/timezone, SNMPv3-only, default-admin removal, virtual patching state, certificate validity (weak algos, self-signed, expired).

VPN Posture

IPsec & SSL VPN.

Cipher inventory, dial-up policy hygiene, weak-cipher detection, split-tunnel review.

Network & VDOM

Segmentation hygiene.

VLAN segmentation, VDOM scope, default-gateway sanity, routing posture (BGP/OSPF).

Logging & FortiAnalyzer

Telemetry sanity-check.

Syslog targets, log-disk usage, retention windows, FortiAnalyzer integration health, encrypted-log enforcement. The signal-loss vector that defeats incident response.

Policy X-Ray

Action Board + Classic Matrix.

Action Board ranks policies by risk (ISDB-weighted destinations); Classic Matrix renders the L4 traffic + L7 node status dashboard. Two views, one X-Ray.

The Domino Effect

Cascading L7 blindness, surfaced.

A gap in SSL inspection cascade-blinds every downstream L7 control on HTTPS (WebFilter, AV, IPS, AppControl). The Action Board renders the propagation per policy, so the root-cause fix is one click.

Hygiene Engine

Zombies. Stale rules. Shadows.

Hit_count = 0 with traffic telemetry collected (zombie rules), last_used_at > 90 days (stale rules), broader policies earlier in the rule list (shadowed rules), broken address objects, dependency-resolved unused profiles. The cleanup nobody dared start, scoped.

Inside the X-Ray

Click a node.
See what is really configured.

FortiGate Policy X-Ray with the SSL inspection node opened, showing certificate-only inspection and the per-protocol table
Every node opens. Here SSL inspection is set to certificate-only, so the HTTPS payload is never decrypted and every downstream control on that traffic is flying blind. The advisory says so in one line.
FortiGate Classic Matrix listing every rule with source, destination, service, action, hit counts and last-seen
Or read the whole rule base at once. The Classic Matrix lays out every rule with its real source, destination, service, hit count, and last-seen. Sort by hits to find the rules doing nothing, or the any-to-any rule doing far too much.
Change Validation · Policy Simulator

Test the change
before you touch the firewall.

Every firewall change is a small act of faith. You edit a rule, push it, and hope nothing three rules down quietly breaks. The simulator removes the faith. Describe a flow, and Retrievy traces it through the live rule set the way FortiOS would, then tells you what actually happens, and what would still happen if you deleted the rule.

Retrievy FortiGate Policy Simulator tracing a permitted flow: source, ingress interface, firewall, egress, destination, with matched rule, rule trace, recommendations and confidence grade

A permitted flow from the LAN to the internet, traced end to end, with the matched rule and its confidence grade.

End-to-end path

The whole path, not a guess.

Interface and route lookup, first-match policy, NAT, then egress. The full path a packet takes, drawn as a topology with the matched rule called out. When the flow is blocked, the traffic stops at the firewall and the verdict turns red. No ambiguity about what would have happened.

Honest by design

It tells you what it cannot see.

A config-only simulator reasons from the saved device state. Matches that hinge on an authenticated user, ZTNA, an ISDB or FQDN object, or runtime routing are labelled uncertain with a caveat, never dressed up as a confident allow. Every verdict carries a confidence grade, so you know when to trust it and when to verify by hand.

Fall-through cascade

What still permits it if you delete the rule.

The rule that matches first is rarely the only rule that would permit the flow. The simulator lists every rule below it that would still allow the traffic, so you know whether deleting one actually closes the path or just shifts it down the list. And it is strictly read-only. It never touches the device.

Hygiene & Cleanup

The cleanup nobody dared start,
scoped with proof.

Nobody deletes a firewall rule on a hunch. So rules accumulate for years, each one a small "probably still needed." The Hygiene board replaces the hunch with hit-count evidence: which rules matched zero traffic since telemetry began, which have been idle past the 90-day threshold, and which reference address groups that resolve to nothing.

FortiGate Hygiene Action Board showing a zombie rule with zero hits, a stale rule idle 126 days, and a policy referencing an empty address group

The Action Board: one zombie rule, one stale rule, one broken traffic path. Each with the evidence to act.

Critical · Zombie rules

Zero hits, confirmed.

An enabled rule that has matched nothing since hit-count telemetry began is an active attack surface with no operational justification. The board names it and shows how long the counter has sat at zero, so the deletion is a decision, not a gamble.

Warning · Stale rules

Idle past the threshold.

A rule that carried traffic once but has been silent for more than 90 days is usually a project that ended without a ticket to close it. The board shows the last-matched date and the exact idle count, ready to paste into the change request.

High · Broken paths

Empty address objects.

A policy that references an address group with no members silently matches nothing. Traffic you believe is permitted fails, and the rule that should explain it looks perfectly healthy in the GUI. The board names the empty group behind the break.

03 — Easy to Fix

FortiOS GUI path + CLI block.
On every finding.

Critical Policy 47 · SSL inspection set to certificate-inspection
What this check validates

Verifies that policies handling outbound HTTPS use SSL/TLS deep inspection, not certificate inspection alone. Without deep inspection, every downstream L7 control (WebFilter, AV, IPS, AppControl) is blind to HTTPS payloads.

FortiOS GUI path
Policy & Objects → Firewall Policy → Edit policy 47
  → Security Profiles → SSL/SSH Inspection
  → "deep-inspection" (or a custom deep-inspection profile)
CLI
config firewall policy
  edit 47
    set ssl-ssh-profile "deep-inspection"
  next
end
References
  • Fortinet · SSL/SSH Inspection profiles
  • CIS Fortinet FortiGate Benchmark · Section 4.2
Hardening Kanban

Engineers don't have to translate from CIS-speak to Fortinet-speak. Each finding ships the GUI path and the CLI block. Copy, paste, verify on the next scan.

Findings flow Triage → Verifying → Hardened. The "Trust but Verify" rule means only the next scan can promote a finding to Hardened. Exceptions live in a separate lane with expiry dates.

Remediation Projects

Group findings.
Ship a sprint.

Some fixes are quick. Others are quarterly initiatives. Multi-finding cleanup work that needs an owner, a deadline, and an audit-ready report at the end. That's a Remediation Project.

Retrievy Remediation Project — Q3 FortiGate Cleanup
Group

One project, many findings.

Bundle related findings under a single project. Use it for "deprecate every Kerberoastable account this quarter", "remediate the EU cloud baseline before audit season", or "clean up the FortiGate rule debt".

Track

Owner. Deadline. Observation log.

Each project has an accountable owner, a target date, and a chronological observation log: who changed what, when, and why. The audit trail is intact by default.

Report

Auto-generate a PDF on close.

When the project closes, Retrievy renders a PDF report. Scope, finding inventory, before-and-after posture, observation timeline. Hand it to your auditor without writing a single line.

Verify

Trust but Verify, project-wide.

Findings inside a project still follow the scan-verified status model. The next scan promotes them to Resolved. The project closes when every finding it contains is verified.

Compliance Coverage

Three frameworks, one config finding.

FortiGate admin-plane and L7 inspection checks roll up to the international benchmarks and the proprietary hygiene rules that catch the risk standards leave behind.

CIS Fortinet FortiGate Benchmark

CIS Fortinet FortiGate 7.0.x v1.4.0 and 7.4.x v1.0.x benchmarks. Full coverage of the 28 admin-plane checks plus the L7 deep-inspection sections (SSL, AV, IPS, AppControl, WebFilter, DNS, DLP, Policy).

NIST SP 800-53 Rev 5

System and Communications Protection (SC), System and Information Integrity (SI), and Access Control (AC) families mapped per finding. Network-device controls tied directly to the audit row.

Retrievy FortiGate Hygiene

Proprietary policy-hygiene engine: rule sprawl, shadowed and unused rules, any-to-any policies, idle objects, and L7 inspection gaps. Surfaces operational risk the standards do not name.

Also auto-mapped to
NIST CSF 2.0 MITRE ATT&CK (Network techniques) ISO/IEC 27001:2022 (network controls) PCI DSS 4.0 (network segmentation)
Frequently Asked

FortiGate audit, answered.

No. A read-only admin profile is enough. The collector connects over SSH with read-only credentials and never has the privilege to modify the device.
Over a read-only SSH session. The collector logs in with a read-only admin profile, gathers the device configuration, and ships it (encrypted) to the Retrievy platform. Analysis runs server-side. No REST endpoints, no API tokens that grant write.
Complementary, not redundant. FortiManager shows you the management copy of the configuration. Retrievy reads the live device and detects when the live config has drifted from what FortiManager believes is deployed.
The Drift Engine filters out routine, expected change before comparing snapshots, so signature updates and rolling counters never trigger an alert. A real configuration change (a policy edit, a profile flip) produces a single, accurate event.
A visualization of cascading L7 inspection failures. If SSL/TLS deep inspection is missing or misconfigured on a policy, every downstream control on HTTPS traffic (WebFilter, AV, IPS, AppControl) goes blind. The Action Board surfaces this propagation per policy, so the root-cause fix is obvious.
You describe a flow (source, destination, protocol, port) and the simulator traces it through the live rule set the way FortiOS would: interface and route lookup, first-match policy, NAT, then egress. It tells you which rule matches, whether the traffic is permitted or dropped, and which other rules would still permit it if you deleted the first one. It is a way to answer "what happens if I change this rule?" before you touch the firewall.
It is strictly read-only and never touches the device. It reasons from the saved configuration, so it is honest about its limits: matches that depend on authenticated users, ZTNA, ISDB, FQDN objects, or runtime routing are labelled uncertain with a caveat rather than reported as a confident allow. Every result carries a confidence grade so you know when to trust it and when to verify by hand.
Yes. The collector reads from the active member; HA cluster state is parsed and surfaced in the dashboard. Drift across the cluster (e.g., out-of-sync members) is flagged.
Yes. The FortiGate scanner ships as a containerised collector for Linux hosts in addition to the Windows agent. Same auth, same offline queue, same outbound-only HTTPS posture.

Audit the box,
not the checklist.

Connect your first FortiGate in three minutes. The first L7 efficacy report and Policy X-Ray appear the same day.

Try everything free for 14 days on your own data. Request your trial code. No credit card required.