3.4.2.3 Ensure IPv6 outbound and established connections are configured

Information

Configure the firewall rules for new outbound, and established connections.

Rationale:

If rules are not in place for new outbound, and established connections all packets will be dropped by the default policy preventing network usage.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure ip6tables in accordance with site policy. The following commands will implement a policy to allow all outbound connections and all established connections:

# ip6tables -A OUTPUT -p tcp -m state --state NEW,ESTABLISHED -j ACCEPT

# ip6tables -A OUTPUT -p udp -m state --state NEW,ESTABLISHED -j ACCEPT

# ip6tables -A OUTPUT -p icmp -m state --state NEW,ESTABLISHED -j ACCEPT

# ip6tables -A INPUT -p tcp -m state --state ESTABLISHED -j ACCEPT

# ip6tables -A INPUT -p udp -m state --state ESTABLISHED -j ACCEPT

# ip6tables -A INPUT -p icmp -m state --state ESTABLISHED -j ACCEPT

See Also

https://workbench.cisecurity.org/benchmarks/6709

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: fb45e1cd5040d90002954cec44b544dae331a1aef76648498a43381ded5714e3