Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 2 checks on this page
- 4.1 Configure Uncomplicated Firewall
- Ensure ufw service is configured
- Ensure ufw is installed
4.1 Configure Uncomplicated Firewall
Ensure ufw service is configured
Finding: Ufw service is not enabled and running.
Checks whether the ufw.service systemd unit is unmasked, enabled at boot, and currently running.
This rule fails when ufw.service is masked, disabled, or not RUNNING.
Rationale: The ufw service must be enabled and active for the host firewall to load and enforce its rules.
Impact: Enabling the firewall while connected over the network can drop existing connections and lock out remote access if an allow rule for SSH is not present.
Remediation
From the command line:
systemctl unmask ufw.service
systemctl --now enable ufw.service
ufw enable
- Framework mappings
- CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure ufw is installed
Finding: Ufw package is not installed.
Checks that the ufw package is installed.
This rule fails when the package is not installed.
Rationale: ufw is the supported host-based firewall frontend for netfilter; without it installed the host has no managed firewall.
Impact: None for installation; changing firewall rules over a network session can lock out remote access.
Scope: Ubuntu 24.04 and later endpoints.
Remediation
From the command line:
apt install ufw
- Framework mappings
- CIS Controls v8: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- NIST SP 800-53 Rev. 5: CA-9 Internal System Connections; SC-7 Boundary Protection
- PCI DSS v4.0.1: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)