35.1 (L1) Ensure 'Enable Domain Network Firewall' is set to 'True'

Information

Select True (recommended) to have Windows Firewall with Advanced Security use the settings for this profile to filter network traffic. If you select False, Windows Firewall with Advanced Security will not use any of the firewall rules or connection security rules for this profile.

The recommended state for this setting is: True

If the firewall is turned off all traffic will be able to access the system and an attacker may be more easily able to remotely exploit a weakness in a network service.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to True :

Firewall\Enable Domain Network Firewall

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Windows

Control ID: 20be7d99ae68334b8357d0e734e2893d0768066491da8f45caaec83b7bb1781c