4.3.3 Ensure that IPsec filters are active

Information

Rules added to the filter list are not enabled automatically. Filters need to be activated and/or updated after changes to the ODM filter database.

Rationale:

The filters must be active in order for IP Security to protect the system.

Impact:

Changing firewall settings while connected over network can result in being locked out of the system.

Ensure you have access to the console (e.g., via HMC) while developing and testing IPsec rule modifications.

Solution

mkfilt -u
mkfilt g start

Additional Information:

In the event that you are locked out of the system by firewall rules, run mkfilt -d from the console to deactivate all filters

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5)

Plugin: Unix

Control ID: 975ec0941a2d4aca5cc427e6f53b456ea981c828747d88eb4058f86698bedfb0