3.4.2.2 Ensure firewalld service enabled and running

Information

firewalld.service enables the enforcement of firewall rules configured through firewalld

Ensure that the firewalld.service is enabled and running to enforce firewall rules configured through firewalld

Solution

Run the following command to unmask firewalld

# systemctl unmask firewalld

Run the following command to enable and start firewalld

# systemctl --now enable firewalld

Impact:

Changing firewall settings while connected over network can result in being locked out of the system.

See Also

https://workbench.cisecurity.org/benchmarks/15965

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 166617bbcefde98ae60dfa20fea99dca191af47e7435f04bc946fdfab530b944