4.1.5 Ensure ufw routed default is configured

Information

The default policy for routed traffic determines if UFW forwards traffic between different network interfaces without requiring specific UFW rules.

A default disabled or deny policy ensures that UFW does not forward traffic between different network interfaces by default. This reduces the risk from unwanted or malicious routed traffic.

Solution

Run the following command to set the defalut for routed to disabled :

# ufw default disabled routed

Impact:

Any port and protocol will be prevented for being routed.

See Also

https://workbench.cisecurity.org/benchmarks/24932

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CCI|CCI-000382, CSCv7|9.4

Plugin: Unix

Control ID: 49824ef889b8d48c953586d3e6e57f278beff13f80cece5e6aed7c853312d9c3