1.2.1.1.1.2.4 Configure 'Windows Firewall: Allow local port exceptions'

Information

The Windows Firewall port exceptions list should be defined by Group Policy, which allows you to centrally manage and deploy your port exceptions and ensure that local administrators do not create less secure settings. Granting port exeptions could expose the computer to network-based attacks, however not allowing any exceptions is likely to break some applications such as computer management tools

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile\Windows Firewall- Allow local port exceptions

Impact- If you enable the Windows Firewall- Define inbound port exceptions setting, you can view and change the port exceptions list that is defined by Group Policy. To view and modify the port exceptions list, configure the setting to Enabled and then click the Show button. Note that if you type an invalid definition string, Windows Firewall adds it to the list without checking for errors, which means that you can accidentally create multiple entries for the same port with Scope or Status values that conflict. If you disable the Windows Firewall- Define inbound port exceptions setting, the port exceptions list that is defined by Group Policy is deleted but other settings can continue to open or block ports. Also, if a local port exceptions list exists, it is ignored unless you enable the Windows Firewall- Allow local port exceptions setting. Note If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall- Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall- Allow inbound file and printer sharing exception, Windows Firewall- Allow inbound remote administration exception, and Windows Firewall- Define inbound port exceptions.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(5), CCE|CCE-17067-0

Plugin: Windows

Control ID: 767df2a021d5bb3094bccb8dcf45059936471c8a05f3872c614a4f67c13e96a4