2.6.4 Enable Firewall Stealth Mode

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Stealth mode on the firewall minimizes the threat of system discovery tools while connected to a network or the Internet.

Solution

Perform the following to implement the prescribed state:
Open System Preferences
Select Security & Privacy
Select Firewall Options
Select Enable stealth mode
Alternatively: Run the following command in Terminal:
sudo /usr/libexec/ApplicationFirewall/socketfilterfw `--setstealthmode on

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.10_Benchmark_v1.1.0.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CSCv6|9.2

Plugin: Unix

Control ID: 1e2d2d795dc1b13d832bf841a412593619af40e1a1d6087f0718b93e8e272f74