Example topics

Hardening topics

Common FortiGate issues the licensed product is designed to surface. These are examples with public-guidance notes, not statistics from a XilonSec customer dataset.

Not a vulnerability feed. There is no published XilonSec incident count on this page. For product findings from your own configs, request a demo.

Example · Admin exposure

HTTP and Telnet on WAN management

Allowing unencrypted administration (HTTP or Telnet) on WAN-facing interfaces exposes credentials and session traffic. Restrict management to HTTPS/SSH, trusted hosts, and a dedicated management interface where possible.

Fortinet documents this class of control in FortiOS administration and hardening guidance.

Example · VPN cryptography

Weak Diffie-Hellman groups in IPsec phase 1

DH groups 1, 2, and 5 are considered weak for modern IPsec. Prefer group 14 or stronger (or the equivalent your FortiOS release supports) and disable obsolete proposals on production tunnels.

Confirm supported groups for your FortiOS version before changing production VPNs.