9.2.4 Ensure 'Windows Firewall: Private: Display a notification' is set to 'No'

Information

Select this option to have Windows Firewall with Advanced Security display notifications to the user when a program is blocked from receiving inbound connections.

The recommended state for this setting is: 'No'.

Note: When the 'Apply local firewall rules' setting is configured to 'No', it's recommended to also configure the 'Display a notification' setting to 'No'.

Otherwise, users will continue to receive messages that ask if they want to unblock a restricted inbound connection, but the user's response will be ignored.

Solution

To establish the recommended configuration via GP, set the following UI path to 'No:'

Computer Configuration\Policies\Windows Settings\Security Settings\Windows Firewall with Advanced Security\Windows Firewall with Advanced Security\Windows Firewall Properties\Private Profile\Settings Customize\Display a notification

See Also

https://workbench.cisecurity.org/files/1941

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4(5)

Plugin: Windows

Control ID: b6cfad82d7248bf15f66ade42f9d25a06f1bc7d888f039eda95d7cf52d702f37