3.6.2.1 Ensure ufw service is enabled - ufw

Information

UncomplicatedFirewall (ufw) is a frontend for iptables. ufw provides a framework for managing netfilter, as well as a command-line and available graphical user interface for manipulating the firewall.

Ensure that the ufw service is enabled to protect your system.

Rationale:

The ufw service must be enabled and running in order for ufw to protect the system

Impact:

Changing firewall settings while connected over network can result in being locked out of the system.

Solution

Run the following command to enable ufw:

# ufw enable

See Also

https://workbench.cisecurity.org/files/2971

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv7|9.4

Plugin: Unix

Control ID: 33959686e58c69895cf2bb43a500570bd848265ad3f9d446ace5ac801c0db9c3