Catalina - Enable Firewall Logging

Information

Firewall logging _MUST_ be enabled.

Firewall logging ensures that malicious network activity will be logged to the system.

NOTE: The firewall data is logged to Apple's Unified Logging with the subsystem com.apple.alf and the data is marked as private.

Solution

[source,bash]
----
/usr/libexec/ApplicationFirewall/socketfilterfw --setloggingmode on
----

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AU-12, 800-53|CM-6b., 800-53|SC-7, CCE|CCE-84757-4, CCI|CCI-000366

Plugin: Unix

Control ID: cc7d779510822cf5de9c72ea72a0a343a1cfea93e807c59d17b3d5f25ca8386a