2.6.4 Enable Firewall Stealth Mode

Information

While in Stealth mode the computer will not respond to unsolicited probes, dropping that traffic. http://support.apple.com/en-us/HT201642 Stealth mode on the firewall minimizes the threat of system discovery tools while connected to a network or the Internet.

Solution

Perform the following to implement the prescribed state: Open System Preferences Select Security & Privacy Select Firewall Options Select Enable stealth mode Alternatively: Run the following command in Terminal: sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setstealthmode on Impact: Traditional network discovery tools like ping will not succeed. Other network tools that measure activity and approved applications will work as expected.

See Also

https://workbench.cisecurity.org/files/299

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: Unix

Control ID: f165861f084199a348c77f7fe26773ec228eb45861ab527d447b002d5a14d810