UCF STIG Viewer Logo

The OS X firewall must have logging enabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-59707 AOSX-10-000950 SV-74137r1_rule Medium
Description
Firewall logging must be enabled. This ensures that malicious network activity will be logged to the system.
STIG Date
Apple OS X 10.10 (Yosemite) Workstation Security Technical Implementation Guide 2017-04-06

Details

Check Text ( C-60477r1_chk )
If HBSS is used, this is not applicable.

To check if the OS X firewall has logging enabled, run the following command:

/usr/libexec/ApplicationFirewall/socketfilterfw --getloggingmode | grep on

If the result does not show 'on', this is a finding.
Fix Text (F-65117r1_fix)
To enable the firewall logging, run the following command:

sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setloggingmode on