CIS Ubuntu Linux 24.04 LTS Benchmark · Section 4

Ubuntu 24.04 Host Based Firewall: 2 Checks

Wartiva runs 2 checks for section 4, Host Based Firewall, of the CIS Ubuntu Linux 24.04 LTS Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 2 checks on this page

4.1 Configure Uncomplicated Firewall

Ensure ufw service is configured

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 4.1

Finding: Ufw service is not enabled and running.

Checks whether the ufw.service systemd unit is unmasked, enabled at boot, and currently running.

This rule fails when ufw.service is masked, disabled, or not RUNNING.

Rationale: The ufw service must be enabled and active for the host firewall to load and enforce its rules.

Impact: Enabling the firewall while connected over the network can drop existing connections and lock out remote access if an allow rule for SSH is not present.

Remediation

From the command line:

systemctl unmask ufw.service
systemctl --now enable ufw.service
ufw enable
Framework mappings
  • CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure ufw is installed

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 4.1

Finding: Ufw package is not installed.

Checks that the ufw package is installed.

This rule fails when the package is not installed.

Rationale: ufw is the supported host-based firewall frontend for netfilter; without it installed the host has no managed firewall.

Impact: None for installation; changing firewall rules over a network session can lock out remote access.

Scope: Ubuntu 24.04 and later endpoints.

Remediation

From the command line:

apt install ufw
Framework mappings
  • CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
  • NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
  • PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)