3.4.1.2 Ensure iptables-persistent is not installed with ufw

Information

The iptables-persistent is a boot-time loader for netfilter rules, iptables plugin

Running both ufw and the services included in the iptables-persistent package may lead to conflict

Solution

Run the following command to remove the iptables-persistent package:

# apt purge iptables-persistent

See Also

https://workbench.cisecurity.org/benchmarks/13007

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 349f706661a487019c37347087135ee0e4d768ae8122faa96c57f77d7f8ce42a