---
title: Verify ufw Enabled
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: Docs > Datadog Security > OOTB Rules > Verify ufw Enabled
---

# Verify ufw Enabled
 
## Description{% #description %}

The `ufw` service can be enabled with the following command:

```
$ sudo systemctl enable ufw.service
```

## Rationale{% #rationale %}

The ufw service must be enabled and running in order for ufw to protect the system

## Remediation{% #remediation %}

### Shell script{% #shell-script %}

The following script can be run on the host to remediate the issue.

```bash
#!/bin/bash

# Remediation is applicable only in certain platforms
if dpkg-query --show --showformat='${db:Status-Status}' 'linux-base' 2>/dev/null | grep -q '^installed$' && { ( dpkg-query --show --showformat='${db:Status-Status}' 'ufw' 2>/dev/null | grep -q '^installed$' && dpkg-query --show --showformat='${db:Status-Status}' 'linux-base' 2>/dev/null | grep -q '^installed$' ); }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'ufw.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'ufw.service'
fi
"$SYSTEMCTL_EXEC" enable 'ufw.service'

else
    >&2 echo 'Remediation is not applicable, nothing was done'
fi
```

### Ansible playbook{% #ansible-playbook %}

The following playbook can be run with Ansible to remediate the issue.

```go
- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-UBTU-20-010434
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ufw_enabled

- name: Verify ufw Enabled - Enable service ufw
  block:

  - name: Gather the package facts
    package_facts:
      manager: auto

  - name: Verify ufw Enabled - Enable Service ufw
    ansible.builtin.systemd:
      name: ufw
      enabled: true
      state: started
      masked: false
    when:
    - '"ufw" in ansible_facts.packages'
  when:
  - '"linux-base" in ansible_facts.packages'
  - ( "ufw" in ansible_facts.packages and "linux-base" in ansible_facts.packages )
  tags:
  - DISA-STIG-UBTU-20-010434
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ufw_enabled
```
