3.4.3.8 Ensure nftables rules are permanent

Information

nftables is a subsystem of the Linux kernel providing filtering and classification of network packets/datagrams/frames. The nftables service reads the /etc/sysconfig/nftables.conf file for a nftables file or files to include in the nftables ruleset. A nftables ruleset containing the input, forward, and output base chains allow network traffic to be filtered. Changes made to nftables ruleset only affect the live system, you will also need to configure the nftables ruleset to apply on boot.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Edit the /etc/sysconfig/nftables.conf file and un-comment or add a line with include <Absolute path to nftables rules file> for each nftables file you want included in the nftables ruleset on boot example: # vi /etc/sysconfig/nftables.conf Add the line: include "/etc/nftables/nftables.rules"

See Also

https://workbench.cisecurity.org/files/2518

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(3), CSCv7|9.4

Plugin: Unix

Control ID: ebc5b835771980ffb79cd320c1e668d306c17bb22fc6fb004d91c769dcc384de