AOSX-10-000155 - The system firewall must be configured with a default-deny policy.

Information

An approved firewall must be installed and enabled to work in concert with the Mac OS X Application Firewall. When configured correctly, firewalls protect computers from network attacks by blocking or limiting access to open network ports.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install an approved HBSS or firewall solution onto the system and configure it with a default-deny policy.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-10_Workstation_V1R5_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Group-ID|V-59577, Rule-ID|SV-74007r1_rule, STIG-ID|AOSX-10-000155

Plugin: Unix

Control ID: 0567b5a08a44c5c0e1799964b474210bc9d12da33fa917d98c113b3d061141ee