Information
Ensure that the final rule in the rulebase explicitly drops all services, destinations, etc not specifically allowed in the previous rules. It is important that any access not explicitly allowed be explicitly dropped.
Rationale:
The Clean up rule is necessary to block all the traffic which is not allowed by earlier rules in the firewall. Ideally, Clean up rule be at the bottom in the Firewall rule base. By default an Implied Rule in Checkpoint firewall which does the same thing, but logging is not enabled for this rule.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Create or edit the last rule in the rulebase which is denying all traffic from any source to any destination.