3.5.1.2 Ensure iptables-services not installed with firewalld

Information

The iptables-services package contains the iptables.service and ip6tables.service. These services allow for management of the Host Based Firewall provided by the iptables package.

Rationale:

iptables.service and ip6tables.service are still supported and can be installed with the iptables-services package. Running both firewalld and the services included in the iptables-services package may lead to conflict.

Impact:

Running both firewalld and iptables/ip6tables service may lead to conflict.

Solution

Run the following commands to stop the services included in the iptables-services package and remove the iptables-services package

# systemctl stop iptables
# systemctl stop ip6tables
# yum remove iptables-services

See Also

https://workbench.cisecurity.org/files/3636

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|CM-6, 800-53|CM-7, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 16cf89ffb5f79fa5d3f4c1d268a9e57ce617e95afdbbc4704c3ceb64f5020720