3.5.1.3 Ensure nftables is not installed or stopped and masked - masked

Information

nftables is a subsystem of the Linux kernel providing filtering and classification of network packets/datagrams/frames and is the successor to iptables.

Rationale:

Running both firewalld and nftables may lead to conflict.

Note: firewalld may configured as the front-end to nftables. If this case, nftables should be stopped and masked instead of removed.

Solution

Run the following command to remove nftables:

# yum remove nftables

See Also

https://workbench.cisecurity.org/files/2948

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, 800-53|CM-7(4), CSCv7|9.4

Plugin: Unix

Control ID: 2d862949121e61b2e2ba0fd1b0d29ce52b9cc42f001904f27e5b669d27b95d24