4.1.1 Ensure 'Enable firewall traversal from remote access host' is set to 'Disabled'

Information

Chrome enables the usage of STUN servers which allows remote clients to discover and connect to a machine even if they are separated by a firewall. By disabling this feature, in conjunction with filtering outgoing UDP connections, the machine will only allow connections from machines within the local network.
Rationale:
If this setting is enabled, remote clients can discover and connect to this machines even if they are separated by a firewall.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled.
Computer Configuration\Administrative Templates\Google\Google Chrome\Configure remote access options\Enable firewall traversal from remote access host
Impact:
If this setting is disabled and outgoing UDP connections are filtered by the firewall, this machine will only allow connections from client machines within the local network.
Default Value:
Enabled.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4, CSCv6|9

Plugin: Windows

Control ID: 96001838b094dc2ac988613aa27f35c1a5ef0a502b18bdb447a751679c49ac50