3.5.2.3 Ensure iptables-services package is not installed

Information

The iptables-services package contains the iptables.service and ip6tables.service. These services allow for management of the Host Based Firewall provided by the iptables package.

Rationale:

iptables.service and ip6tables.service are still supported and can be installed with the iptables-services package. Running both nftables and the services included in the iptables-services package may lead to conflict.

Solution

Run the following commands to stop the services included in the iptables-services package and remove the iptables-services package

# systemctl stop iptables
# systemctl stop ip6tables

# yum remove iptables-services

See Also

https://workbench.cisecurity.org/files/2851

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4)

Plugin: Unix

Control ID: e68abc36e50ed7ba99c478db728bd2ccc84bb710b560efde0b7bd8b64d713e2f