3.6.2.2 Ensure Uncomplicated Firewall is not installed or disabled

Information

Uncomplicated Firewall (UFW) is a program for managing a netfilter firewall designed to be easy to use.

Rationale:

Running both the nftables service and ufw may lead to conflict and unexpected results.

Solution

Run one of the following commands to either remove ufw or disable ufw
Run the following command to remove ufw:

# apt purge ufw

Run the following command to disable ufw:

# ufw disable

See Also

https://workbench.cisecurity.org/files/2920

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv7|9.4

Plugin: Unix

Control ID: 4334c1711d64bb91d9267fb95566a28a951fede6ce4eabac77e7bcc892ab14a0