---
title: CIS Ubuntu 24.04 Host Based Firewall: 2 Checks | Wartiva
description: Wartiva's 2 checks for section 4, Host Based Firewall, of the CIS Ubuntu Linux 24.04 LTS Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/host-based-firewall.html
updated: 2026-10-07
---

CIS Ubuntu Linux 24.04 LTS Benchmark · Section 4

# Ubuntu 24.04 Host Based Firewall: 2 Checks

Wartiva runs 2 checks for section 4, Host Based Firewall, of the CIS Ubuntu Linux 24.04 LTS Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## 4.1 Configure Uncomplicated Firewall

### [Ensure ufw service is configured](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/host-based-firewall.html#ufw-service-is-configured)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 4.1

**Finding:** Ufw service is not enabled and running.

Checks whether the ufw.service systemd unit is unmasked, enabled at boot, and currently running.

This rule fails when `ufw.service` is masked, disabled, or not `RUNNING`.

**Rationale:** The ufw service must be enabled and active for the host firewall to load and enforce its rules.

**Impact:** Enabling the firewall while connected over the network can drop existing connections and lock out remote access if an allow rule for SSH is not present.

#### Remediation

From the command line:

```sh
systemctl unmask ufw.service
systemctl --now enable ufw.service
ufw enable
```

Framework mappings

- **CIS Controls v8**: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- **NIST SP 800-53 Rev. 5**: CA-9 Internal System Connections; SC-7 Boundary Protection
- **PCI DSS v4.0.1**: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure ufw is installed](https://wartiva.com/policy-rules/ubuntu-linux-24-04-lts/host-based-firewall.html#ufw-is-installed)

Medium severity · Wartiva check · CIS Ubuntu Linux 24.04 LTS Benchmark 4.1

**Finding:** Ufw package is not installed.

Checks that the ufw package is installed.

This rule fails when the package is not installed.

**Rationale:** ufw is the supported host-based firewall frontend for netfilter; without it installed the host has no managed firewall.

**Impact:** None for installation; changing firewall rules over a network session can lock out remote access.

**Scope:** Ubuntu 24.04 and later endpoints.

#### Remediation

From the command line:

```sh
apt install ufw
```

Framework mappings

- **CIS Controls v8**: 4.4 Implement and Manage a Firewall on Servers; 4.5 Implement and Manage a Firewall on End-User Devices
- **NIST SP 800-53 Rev. 5**: CA-9 Internal System Connections; SC-7 Boundary Protection
- **PCI DSS v4.0.1**: 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.4.1 Deploy NSCs where trusted networks meet untrusted ones

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
