9.1.4 Ensure 'Windows Firewall: Domain: Settings: Display a notification' is set to 'No'

Information

Select this option to have Windows Firewall with Advanced Security display notifications to the user when a program is blocked from receiving inbound connections.

The recommended state for this setting is: 'No'.

Note: When the 'Apply local firewall rules' setting is configured to 'No', it's recommended to also configure the 'Display a notification setting' to 'No'. Otherwise, users will continue to receive messages that ask if they want to unblock a restricted inbound connection, but the user's response will be ignored.

Rationale:
Firewall notifications can be complex and may confuse the end users, who would not be able to address the alert.

Solution

To establish the recommended configuration via GP, set the following UI path to 'No':


Computer Configuration\Policies\Windows Settings\Security Settings\Windows Firewall with Advanced Security\Windows Firewall with Advanced Security\Windows Firewall Properties\Domain Profile\Settings Customize\Display a notification


Impact:
Windows Firewall will not display a notification when a program is blocked from receiving inbound connections.

See Also

https://workbench.cisecurity.org/files/1949

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4(5), CCE|CCE-38041-0

Plugin: Windows

Control ID: 3ca801d5c7bd87743c50f86494f1080d7cf9abd0501252eabf24932ffc8350d3