Drop in the configuration backup your firewall already makes. Every password and
key is stripped out first, then it is checked for the mistakes behind most FortiGate
break-ins, here in your browser.
Or paste the configuration
Secrets stripped before reading
The file never leaves this browser
Try it offline: it still works
Example report
FortiGate 60F, FortiOS 7.2.8
6 things to fix first
Flaws attackers are using3
Admin page open to the internet1
VPN accounts without MFA2
More in the full report●●●
Removing passwords, keys and certificates
Reading the configuration in your browser
Checking the firmware against the exploited list
Checking access, rules, VPN and logging
Firewall report
1 Summary
What the file shows
2 Findings
3 What this could not check
Firmware is checked against CISA’s Known Exploited Vulnerabilities catalogue,
with affected versions from NIST’s National Vulnerability Database. Guidance, not an audit
or a penetration test; see the terms.
HOW TO GET THE FILE
Your configuration, exported
The backup your firewall already makes. Save it without a password, so the browser can read it.
Open the backup pageClick your admin name at the top right, then Configuration › Backup. On older firmware: System › Configuration › Backup.
Leave encryption offAn encrypted backup cannot be read by the browser. The check strips every secret before reading anyway.
Save the .conf fileThen drop it in above. Nothing is uploaded: you can disconnect from the internet first, and it still works.
Open the CLIThe CLI console on the dashboard, or SSH from inside the network.
Run two commandsget system status, then show full-configuration. The first gives the firmware version.
Paste bothInto “Or paste the configuration” above. Long output is fine.
What is removed before reading: passwords and password hashes, VPN pre-shared
keys, private keys and certificates, SNMP community strings, and anything stored encrypted
(ENC). The report states what it found in plain words, and never quotes your configuration.
QUESTIONS
Asked often
The questions people search for before they run the check.
How do I check if my FortiGate is vulnerable?
Compare its firmware version with the fixed versions in Fortinet's advisories, starting with the flaws CISA lists as exploited in real attacks. This check does that from the backup file, and also looks at the settings attackers rely on: management open to the internet, SSL-VPN without a second factor, and rules that let anything in.
Is my configuration uploaded anywhere?
No. The file is read in your browser and never sent to us. Passwords, keys, certificates and SNMP communities are removed before anything is read, and the report never quotes a line of the configuration. You can disconnect from the internet after the page loads and it still works.
How do I back up a FortiGate configuration?
In the web interface, click your admin name at the top right, then Configuration and Backup, and save it without encryption. From the CLI, show full-configuration prints the same thing; add the first line of get system status for the firmware version.
Should the FortiGate admin page be reachable from the internet?
No. Management access (HTTPS, SSH, FortiManager) on an internet-facing interface is how many FortiGate compromises start. Manage it from inside the network or over the VPN, and set trusted hosts on every admin account.
Does FortiGate SSL-VPN need MFA?
It should. A VPN account with a password alone turns one leaked password into a way into the network. FortiToken, or MFA at a RADIUS or SAML provider, closes that. Fortinet also recommends moving remote access to IPsec VPN where the model supports it.
Where does the list of exploited flaws come from?
From CISA's Known Exploited Vulnerabilities catalogue, with the affected FortiOS versions from NIST's National Vulnerability Database. The report prints the date the list was refreshed, and warns when it is more than 14 days old.
Godwit AI Labs
This report is available as a branded PDF. Use “Download the report” on the page,
or ask us for the detailed report at godwit-tech.com/contact.
Rather we went through it with you?
Every rule, the firmware path for your model, remote access and logging, then the changes
applied in one maintenance window, each with a way back.