1.2.1.1.1.2.10 Configure 'Windows Firewall: Protect all network connections'

Information

This policy setting enables Windows Firewall, which replaces Internet Connection Firewall on all computers that run Windows Vista. If Windows Firewall: Protect all network connections is configured to Disabled, Windows Firewall is turned off and all other settings for Windows Firewall are ignored. This exposes the computer to potential network-based attacks.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile\Windows Firewall- Protect all network connections

Impact- None, this is the default configuration. If you enable this policy setting, Windows Firewall runs and ignores the setting for

Computer Configuration\Administrative Templates\Network\Network Connections \Prohibit use of Internet Connection Firewall on your DNS domain network.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CCE|CCE-17362-5, CSCv6|9.2

Plugin: Windows

Control ID: a6d2f4b7b0bc0bfe05df036b2a04e678da4ebf98527c4714a1035043453f0a3c