35.17 (L1) Ensure 'Enable Public Network Firewall: Allow Local Policy Merge' is set to 'False'

Information

This setting controls whether local administrators are allowed to create local firewall rules that apply together with firewall rules configured by Group Policy.

The recommended state for this setting is: False

Note: When the Allow Local Policy Merge setting is configured to False it's recommended to also configure the Disable Inbound Notifications setting to True Otherwise, users will continue to receive messages that ask if they want to unblock a restricted inbound connection, but the user's response will be ignored.

When in the Public profile, there should be no special local firewall exceptions per computer. These settings should be managed by a centralized policy.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to False :

Firewall\Enable Public Network Firewall: Allow Local Policy Merge

Impact:

Administrators can still create firewall rules, but the rules will not be applied.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4, CSCv7|11.3

Plugin: Windows

Control ID: 94ce91802db385424b8ec7df9841b2fbe724f99f714f415fc0f5b9b7ca03108c