4.1.5 Ensure ufw routed default is configured

Information

The default policy for routed traffic determines if UFW forwards traffic between different network interfaces without requiring specific UFW rules.

A default deny policy ensures that UFW does not forward traffic between different network interfaces by default. This reduces the risk from unwanted or malicious routed traffic.

Solution

Run the following command to set the default policy for routed to deny :

# ufw default deny routed

Impact:

Any port and protocol will be prevented for being routed.

See Also

https://workbench.cisecurity.org/benchmarks/24330

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CCI|CCI-000382, CSCv7|9.4

Plugin: Unix

Control ID: 95ea9bf43a24a4b496465d7a5d557f230c6afccacf5fa685c6dc390c88c6f1bf