3.5.1.5 Ensure ufw outbound connections are configured

Information

Configure the firewall rules for new outbound connections.

Notes:

Changing firewall settings while connected over network can result in being locked out of the system.

Unlike iptables, when a new outbound rule is added, ufw automatically takes care of associated established connections, so no rules for the latter kind are required.

Rationale:

If rules are not in place for new outbound connections all packets will be dropped by the default policy preventing network usage.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure ufw in accordance with site policy. The following commands will implement a policy to allow all outbound connections on all interfaces:

# ufw allow out on all

See Also

https://workbench.cisecurity.org/files/3219

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv7|9.4

Plugin: Unix

Control ID: 55ad5c6dd6ae0814716e8ef26faa1888e439955a7bc3be62583cf39693972775