AOSX-11-000155 - The system firewall must be configured with a default-deny policy.

Information

An approved firewall must be installed and enabled to work in concert with the OS X Application Firewall. When configured correctly, firewalls protect computers from network attacks by blocking or limiting access to open network ports.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Install an approved HBSS or firewall solution onto the system and configure it with a "default-deny" policy.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-11_V1R6_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Rule-ID|SV-82031r1_rule, STIG-ID|AOSX-11-000155, Vuln-ID|V-67541

Plugin: Unix

Control ID: 3d84cb70880cc565c5929e697a2ef50560a7373f5aa49a0fb5a69295d9b5eb33