Catalina - Enable macOS Application Firewall

Information

The macOS Application Firewall is the built-in firewall that comes with macOS, and it _MUST_ be enabled.

When the macOS Application Firewall is enabled, the flow of information within the information system and between interconnected systems will be controlled by approved authorizations.

Solution

[source,bash]
----
/usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on
----

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-4, 800-53|AC-6(1), 800-53|AC-19, 800-53|CM-6b., 800-53|CM-7, 800-53|CM-7(1), 800-53|SC-7, 800-53|SC-7(12), CCE|CCE-84832-5, CCI|CCI-000366, STIG-ID|AOSX-15-005050

Plugin: Unix

Control ID: 1049644a9b43b5c9f83d03fd1cfc996a57fc001315f1bccfb93b09f5d57ad3f4