3.4.2.3 Ensure iptables-services not installed with nftables

Information

The iptables-services package contains the iptables.service and ip6tables.service These services allow for management of the Host Based Firewall provided by the iptables package.

iptables.service and ip6tables.service are still supported and can be installed with the iptables-services package. Running both nftables and the services included in the iptables-services package may lead to conflict.

Solution

Run the following commands to stop the services included in the iptables-services package and remove the iptables-services package

# systemctl stop iptables
# systemctl stop ip6tables

# dnf remove iptables-services

See Also

https://workbench.cisecurity.org/files/3742

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|CM-6, 800-53|CM-7, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: e520b2f2ae2ff8d838038f9f8e9755ba20fbca3aa8a8bea5020dbf720bf09042