3.6 Ensure Firewall is configured to log

Information

The socketfilter firewall is what is used when the firewall is turned on in the Security PreferencePane. In order to appropriately monitor what access is allowed and denied logging must be enabled.

Rationale:

In order to troubleshoot the successes and failures of a firewall logging should be enabled.

Solution

Run
/usr/libexec/ApplicationFirewall/socketfilterfw --setloggingmode on

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Unix

Control ID: ae0be3799542c53b887cc99d973f7b80741c4b4f554e85b941372ec673e367bd