CIS Microsoft Windows 11 Stand-alone Benchmark · Section 9

Windows 11 Defender Firewall with Advanced Security: 14 Checks

Wartiva runs 14 checks for section 9, Windows Defender Firewall with Advanced Security, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 14 checks on this page

9.2 Private Profile

Ensure Windows Firewall Private Profile Blocked-Program Notifications Are Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.2

Finding: Windows Firewall private profile displays a notification when a program is blocked.

Checks whether the firewall suppresses the pop-up shown to users when a program is blocked from accepting inbound connections on the private profile.

This rule fails when disableNotifications is false.

Rationale: Firewall pop-ups can confuse users, who typically cannot act on them, and may prompt them to weaken protection.

Impact: Users no longer see a notification when a program is blocked from receiving inbound connections.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Settings Customize > Display a notification and set it to No.

From the command line:

netsh advfirewall set privateprofileprofile settings inboundusernotification disable
Framework mappings
  • CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
Risk
External Exposure
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Firewall Private Profile Inbound Connections Are Blocked By Default

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.2

Finding: Windows Firewall private profile does not block inbound connections by default.

Checks the default action for inbound connections that match no firewall rule on the private profile.

This rule fails when defaultInboundAction is not BLOCK_TRAFFIC.

Rationale: If unmatched inbound traffic is allowed, a threat actor can more easily reach and exploit a network service.

Impact: None; this is the default behavior.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Inbound connections and set it to Block (default).

From the command line:

netsh advfirewall set privateprofileprofile firewallpolicy blockinbound,allowoutbound
Framework mappings
  • CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Windows Firewall Private Profile Logging File Path Is Configured

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.2

Finding: Windows Firewall private profile logging file path is not configured.

Checks whether a dedicated log file is configured for the private firewall profile rather than the shared default.

This rule fails when logFilePath is empty or left at the shared default pfirewall.log.

Rationale: Without a dedicated firewall log, administrators may be unable to analyze system issues or trace the activity of a threat actor.

Impact: Firewall log entries for this profile are written to the configured file.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Logging Customize > Name and set it to a dedicated log file path for this profile (for example %SystemRoot%\System32\logfiles\firewall\privatefw.log).

From the command line:

netsh advfirewall set privateprofileprofile logging filename %SystemRoot%\System32\logfiles\firewall\privatefw.log
Framework mappings
  • CIS Controls v8: 8.2 Collect Audit Logs
  • NIST SP 800-53 Rev. 5: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
  • PCI DSS v4.0.1: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry
Risk
External Exposure
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Firewall Private Profile Logging Size Limit Is 16,384 KB Or Greater

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.2

Finding: Windows Firewall private profile logging size limit is below 16,384 KB.

Checks the maximum size, in kilobytes, of the private firewall log file.

This rule fails when logFileSize is less than 16384.

Rationale: A log that is too small overwrites older entries quickly, which can erase evidence needed to investigate an incident.

Impact: The firewall log grows to the configured size before older entries are overwritten.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Logging Customize > Size limit (KB) and set it to 16,384 KB or greater.

From the command line:

netsh advfirewall set privateprofileprofile logging maxfilesize 16384
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
External Exposure
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Firewall Private Profile Logs Dropped Packets

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.2

Finding: Windows Firewall private profile does not log dropped packets.

Checks whether the private firewall records inbound packets that it discards.

This rule fails when logDroppedPackets is false.

Rationale: Without a record of dropped packets it is harder to detect scanning or intrusion attempts and to diagnose connectivity problems.

Impact: Dropped packets are recorded in the firewall log file.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Logging Customize > Log dropped packets and set it to Yes.

From the command line:

netsh advfirewall set privateprofileprofile logging droppedconnections enable
Framework mappings
  • CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices; 8.5 Collect Detailed Audit Logs
  • NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SC-7 Boundary Protection; SI-4 System Monitoring
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
Risk
External Exposure
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Firewall Private Profile Logs Successful Connections

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.2

Finding: Windows Firewall private profile does not log successful connections.

Checks whether the private firewall records inbound connections that it allows.

This rule fails when logSuccessfulConnections is false.

Rationale: Without a record of allowed connections, investigators lack the context needed to reconstruct activity during an incident.

Impact: Successful connections are recorded in the firewall log file.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Logging Customize > Log successful connections and set it to Yes.

From the command line:

netsh advfirewall set privateprofileprofile logging allowedconnections enable
Framework mappings
  • CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices; 8.5 Collect Detailed Audit Logs
  • NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SC-7 Boundary Protection; SI-4 System Monitoring
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
Risk
External Exposure
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Firewall Private Profile State Is On

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.2

Finding: Windows Firewall private profile is turned off.

Checks whether Windows Defender Firewall is turned on for the private network profile.

This rule fails when enableFirewall is false.

Rationale: With the firewall off, all traffic can reach the host and a threat actor can more easily exploit an exposed network service.

Impact: None; this is the default state.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Private Profile > Firewall state and set it to On (recommended).

From the command line:

netsh advfirewall set privateprofileprofile state on
Framework mappings
  • CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

9.3 Public Profile

Ensure Windows Firewall Public Profile Blocked-Program Notifications Are Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.3

Finding: Windows Firewall public profile displays a notification when a program is blocked.

Checks whether the firewall suppresses the pop-up shown to users when a program is blocked from accepting inbound connections on the public profile.

This rule fails when disableNotifications is false.

Rationale: Firewall pop-ups can confuse users, who typically cannot act on them, and may prompt them to weaken protection.

Impact: Users no longer see a notification when a program is blocked from receiving inbound connections.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Settings Customize > Display a notification and set it to No.

From the command line:

netsh advfirewall set publicprofileprofile settings inboundusernotification disable
Framework mappings
  • CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
Risk
External Exposure
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Firewall Public Profile Inbound Connections Are Blocked By Default

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.3

Finding: Windows Firewall public profile does not block inbound connections by default.

Checks the default action for inbound connections that match no firewall rule on the public profile.

This rule fails when defaultInboundAction is not BLOCK_TRAFFIC.

Rationale: If unmatched inbound traffic is allowed, a threat actor can more easily reach and exploit a network service.

Impact: None; this is the default behavior.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Inbound connections and set it to Block (default).

From the command line:

netsh advfirewall set publicprofileprofile firewallpolicy blockinbound,allowoutbound
Framework mappings
  • CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Windows Firewall Public Profile Logging File Path Is Configured

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.3

Finding: Windows Firewall public profile logging file path is not configured.

Checks whether a dedicated log file is configured for the public firewall profile rather than the shared default.

This rule fails when logFilePath is empty or left at the shared default pfirewall.log.

Rationale: Without a dedicated firewall log, administrators may be unable to analyze system issues or trace the activity of a threat actor.

Impact: Firewall log entries for this profile are written to the configured file.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Logging Customize > Name and set it to a dedicated log file path for this profile (for example %SystemRoot%\System32\logfiles\firewall\publicfw.log).

From the command line:

netsh advfirewall set publicprofileprofile logging filename %SystemRoot%\System32\logfiles\firewall\publicfw.log
Framework mappings
  • CIS Controls v8: 8.2 Collect Audit Logs
  • NIST SP 800-53 Rev. 5: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
  • PCI DSS v4.0.1: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry
Risk
External Exposure
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Firewall Public Profile Logging Size Limit Is 16,384 KB Or Greater

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.3

Finding: Windows Firewall public profile logging size limit is below 16,384 KB.

Checks the maximum size, in kilobytes, of the public firewall log file.

This rule fails when logFileSize is less than 16384.

Rationale: A log that is too small overwrites older entries quickly, which can erase evidence needed to investigate an incident.

Impact: The firewall log grows to the configured size before older entries are overwritten.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Logging Customize > Size limit (KB) and set it to 16,384 KB or greater.

From the command line:

netsh advfirewall set publicprofileprofile logging maxfilesize 16384
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
External Exposure
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Firewall Public Profile Logs Dropped Packets

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.3

Finding: Windows Firewall public profile does not log dropped packets.

Checks whether the public firewall records inbound packets that it discards.

This rule fails when logDroppedPackets is false.

Rationale: Without a record of dropped packets it is harder to detect scanning or intrusion attempts and to diagnose connectivity problems.

Impact: Dropped packets are recorded in the firewall log file.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Logging Customize > Log dropped packets and set it to Yes.

From the command line:

netsh advfirewall set publicprofileprofile logging droppedconnections enable
Framework mappings
  • CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices; 8.5 Collect Detailed Audit Logs
  • NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SC-7 Boundary Protection; SI-4 System Monitoring
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
Risk
External Exposure
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Firewall Public Profile Logs Successful Connections

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.3

Finding: Windows Firewall public profile does not log successful connections.

Checks whether the public firewall records inbound connections that it allows.

This rule fails when logSuccessfulConnections is false.

Rationale: Without a record of allowed connections, investigators lack the context needed to reconstruct activity during an incident.

Impact: Successful connections are recorded in the firewall log file.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Logging Customize > Log successful connections and set it to Yes.

From the command line:

netsh advfirewall set publicprofileprofile logging allowedconnections enable
Framework mappings
  • CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices; 8.5 Collect Detailed Audit Logs
  • NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SC-7 Boundary Protection; SI-4 System Monitoring
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
Risk
External Exposure
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Firewall Public Profile State Is On

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 9.3

Finding: Windows Firewall public profile is turned off.

Checks whether Windows Defender Firewall is turned on for the public network profile.

This rule fails when enableFirewall is false.

Rationale: With the firewall off, all traffic can reach the host and a threat actor can more easily exploit an exposed network service.

Impact: None; this is the default state.

Remediation

Open Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Public Profile > Firewall state and set it to On (recommended).

From the command line:

netsh advfirewall set publicprofileprofile state on
Framework mappings
  • CIS Controls v8: 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)