GEN008540 M6 - The system's local firewall must implement a deny-all, allow-by-exception policy

Information

A local firewall protects the system from exposing unnecessary or undocumented network services to the local enclave. If a system within the enclave is compromised, firewall protection on an individual system continues to protect it from attack.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the system's local firewall to implement a deny-all, allow-by-exception policy.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, CCI|CCI-001109, Rule-ID|SV-39384r1_rule, STIG-ID|GEN008540-M6, Vuln-ID|V-22583

Plugin: Unix

Control ID: a591e580755b621f820faa69f50673df8457bb1e5338ea9f8d0147849f6c80d9