3.5.1.3 Ensure nftables either not installed or masked with firewalld - masked

Information

nftables is a subsystem of the Linux kernel providing filtering and classification of network packets/datagrams/frames and is the successor to iptables.

_Note: Support for using nftables as the back-end for firewalld was added in release v0.6.0. In Fedora 19 Linux derivatives, firewalld utilizes iptables as its back-end by default.

Rationale:

Running both firewalld and nftables may lead to conflict.

Note: firewalld may configured as the front-end to nftables. If this case, nftables should be stopped and masked instead of removed.

Solution

Run the following command to remove nftables:

# yum remove nftables

OR
Run the following command to stop and mask nftables'

systemctl --now mask nftables

See Also

https://workbench.cisecurity.org/files/3636

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|CM-6, 800-53|CM-7, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: e91857481906b68d5141f6baa820fd5b418c7690d790dc07182fe578dab57573