4.1.1 Ensure a single firewall configuration utility is in use

Information

In Linux security, employing a single, effective firewall configuration utility ensures that only legitimate traffic gets processed, reducing the system's exposure to potential threats. The choice between ufw nftables and iptables depends on organizational needs.

Note: iptables is being phased out, and support for iptables will be reduced over time. It is recommended to transition towards either nftables or ufw as the default firewall management tool.

Proper configuration of a single firewall utility minimizes cyber threats and protects services and data, while avoiding vulnerabilities like open ports or exposed services. Standardizing on a single tool simplifies management, reduces errors, and fortifies security across Linux systems.

Solution

Remediating to a single firewall configuration is a complex process and involves several steps. The following provides the basic steps to follow for a single firewall configuration:

-

Determine which firewall utility best fits organizational needs

-

Follow the recommendations in the subsequent subsection for the single firewall to be used

Note: Review the firewall subsection overview for the selected firewall to be used, it contains a script tosimplify this process.

-

Return to this recommendation to ensure a single firewall configuration utility is in use

Impact:

The use of more than one firewall utility may produce unexpected results.

See Also

https://workbench.cisecurity.org/benchmarks/18960

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 85b9ab2d54110c4007b7add91a334b69449be1c6f8926cdc2d4da2109012a2d9