Big Sur - Enable macOS Application Firewall

Information

The macOS Application Firewall is the built-in firewall that comes with macOS, and it _MUST_ be enabled.

When the macOS Application Firewall is enabled, the flow of information within the information system and between interconnected systems will be controlled by approved authorizations.

Solution

[source,bash]
----
/usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on
----

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-4, 800-53|AC-6(1), 800-53|AC-19, 800-53|CM-6b., 800-53|CM-7, 800-53|CM-7(1), 800-53|SC-7, 800-53|SC-7(12), CCE|CCE-85427-3, CCI|CCI-000366, STIG-ID|APPL-11-005050

Plugin: Unix

Control ID: a33de35a2608faf051295100d8090a1db0c9a4c9fc564e36815ed1eb8453a8d6