3.4.2.2 Ensure iptables is not enabled - inactive

Information

IPtables is an application that allows a system administrator to configure the IPv4 and IPv6 tables, chains and rules provided by the Linux kernel firewall.
IPtables is installed as a dependency with firewalld.
Rationale:
Running firewalld and IPtables concurrently may lead to conflict, therefore IPtables should be stopped and masked when using firewalld.

Solution

Run the following command to stop and mask iptables
systemctl --now mask iptables

See Also

https://workbench.cisecurity.org/files/2485

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 81e534ad939467ec8bbca995bde0720ca6baa9b2fd736fe5ebc3901d7839e83f