Monterey - Enable Firewall Logging

Information

Firewall logging _MUST_ be enabled.

Firewall logging ensures that malicious network activity will be logged to the system.

NOTE: The firewall data is logged to Apple's Unified Logging with the subsystem `com.apple.alf` and the data is marked as private. In order to enable private data, review the `com.apple.alf.private_data.mobileconfig` file in the project's `includes` folder.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.security.firewall:
EnableLogging:
True
LoggingOption:
detail

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AU-12, 800-53|SC-7, CCE|CCE-90924-2

Plugin: Unix

Control ID: ffdb5bbf2e55916a723897068a38e94cd715f32577901afc6e178cccd26a33ac