3.4.1.6 Ensure network interfaces are assigned to appropriate zone

Information

firewall zones define the trust level of network connections or interfaces.

A network interface not assigned to the appropriate zone can allow unexpected or undesired network traffic to be accepted on the interface.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Run the following command to assign an interface to the approprate zone.

# firewall-cmd --zone=<Zone NAME> --change-interface=<INTERFACE NAME>

Example:

# firewall-cmd --zone=customezone --change-interface=eth0

Impact:

Changing firewall settings while connected over network can result in being locked out of the system.

See Also

https://workbench.cisecurity.org/files/3742

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 8d94f29cca45139d5823faecfb569a5e63dd9b639d948022ceb0cf8ba0161be2