3.4.3.8 Ensure nftables service is enabled and active

Information

The nftables service allows for the loading of nftables rulesets during boot, or starting on the nftables service

The nftables service restores the nftables rules from the rules files referenced in the /etc/sysconfig/nftables.conf file during boot or the starting of the nftables service

Solution

Run the following commands to unmask, enable and start nftables.service :

# systemctl unmask nftables.service
# systemctl --now enable nftables.service

See Also

https://workbench.cisecurity.org/benchmarks/15965

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 8a3d132b0a10a06fbe01905232cbc6bdd575a4fe397bc1c5c9ccfccba8f58465