4.1.4 Ensure ufw default routed is configured

Information

A default deny policy on connections ensures that any unconfigured network usage will be rejected.

Note: Any port or protocol without a explicit allow before the default deny will be blocked

With a default accept policy the firewall will route any packet that is not configured to be denied. Unless a system is specifically intended to be used as a router, traffic should not be routed.

Solution

Run the following command to set the defalut for routed to disabled :

# ufw default disabled routed

Impact:

Any port and protocol will be prevented for being routed

See Also

https://workbench.cisecurity.org/benchmarks/20741

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: f5f7426dacc52e24035a37cc7d89709f463e161bc073cbd16f08b7894a2599ce