Information
The Track Field defines how the events of the rule are captured.
Rationale:
The event log of firewall rules helps in identifying the allowed and blocked traffic and also helps in troubleshooting and forensic investigation. It is always good to enable logging for all the firewall rules, but by logging multiple firewall rules results in a huge log files, which requires huge disk space and management operations. Logs play an important role in security auditing, incident response, system maintenance and forensic investigation, and should be configured as per the business needs.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Set the Track field to Log in all firewall rules.