1.2.1.1.1.1.7 Configure 'Windows Firewall: Allow inbound UPnP framework exceptions'

Information

This policy setting allows a computer to receive unsolicited Plug and Play messages that are sent by network devices, such as routers with built-in firewalls. To receive these messages, Windows Firewall opens TCP port 2869 and UDP port 1900. Blocking UPnP network traffic effectively reduces the attack surface of computers in your environment.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Standard Profile\Windows Firewall- Allow inbound UPnP framework exceptions

Impact- If you enable the Windows Firewall- Allow inbound UPnP framework exceptions setting, Windows Firewall opens these ports so that the computer can receive Plug and Play messages. You must specify the IP addresses or subnets from which these inbound messages are allowed. If you disable this policy setting, Windows Firewall blocks these ports and prevents the computer from receiving Plug and Play messages.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(11), CCE|CCE-17360-9

Plugin: Windows

Control ID: 7f71d2aa3b15bd80f87d9d1c82fdfe64a31b5cabaf97793da127896cfd261e2b