3.5.1.6 Ensure network interfaces are assigned to appropriate zone

Information

firewall zones define the trust level of network connections or interfaces.

Rationale:

A network interface not assigned to the appropriate zone can allow unexpected or undesired network traffic to be accepted on the interface.

Impact:

Changing firewall settings while connected over network can result in being locked out of the system.

Solution

Run the following command to assign an interface to the approprate zone.

# firewall-cmd --zone=<Zone NAME> --change-interface=<INTERFACE NAME>

Example:

# firewall-cmd --zone=customezone --change-interface=eth0

Default Value:

default zone defined in the firewalld configuration

See Also

https://workbench.cisecurity.org/files/3636

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: dd045cc8b4d78cee9ddf003f98848ad8421cca779edd5200c86837eaf4a7d6f5