4.1.1 Ensure ufw is installed

Information

The Uncomplicated Firewall (ufw) is a frontend for iptables and is particularly well-suited for host-based firewalls. ufw provides a framework for managing netfilter, as well as a command-line interface for manipulating the firewall

UFW acts as a frontend for both iptables and nftables and can use either as its backend, though the specific backend depends on the Linux distribution and system configuration.

You can enable the firewall, view its status, and manage rules using simple command-line tools to secure your system.

Solution

Run the following command to install Uncomplicated Firewall (UFW):

# apt install ufw

Impact:

Changing firewall settings while connected over the network can result in being locked out of the system.

See Also

https://workbench.cisecurity.org/benchmarks/24330

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(1), CCI|CCI-002314, CSCv7|9.4, Rule-ID|SV-260514r958672_rule, Rule-ID|SV-270654r1067143_rule, STIG-ID|UBTU-22-251010, STIG-ID|UBTU-24-100300

Plugin: Unix

Control ID: c962d455450795e07d5d9119fd90b43fa86da37f486914d1e834da480aca898d