7.7 Ensure Firewall is active

Information

IPtables is an application that allows a system administrator to configure the IPv4 tables,
chains and rules provided by the Linux kernel firewall. ufw was developed to ease IPtables
firewall configuration.

*Rationale*

IPtables provides extra protection for the Linux system by limiting communications in and
out of the box to specific IPv4 addresses and ports. Ubuntu provides UFW to ease firewall
configuration.

Solution

Activate ufw-# ufw enable
Ensure that any needed ports, such as ssh access, are configured properly first.

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv6|9.2

Plugin: Unix

Control ID: 527eb3046953e67736f446b2b97307f819caff12a99860fa0a58e6597f685549