3.4.3.2 Ensure a table exists

Information

Tables hold chains. Each table only has one address family and only applies to packets of this family. Tables can have one of five families.
Rationale:
nftables doesn't have any default tables. Without a table being build, nftables will not filter network traffic.

Solution

Run the following command to create a table in nftables
# nft create table inet <table name>
Example:
# nft create table inet filter
Impact:
Adding rules to a running nftables can cause loss of connectivity to the system

See Also

https://workbench.cisecurity.org/files/2485

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(15)

Plugin: Unix

Control ID: 71a93684a6ba42eb4053af0fd2c78e8e3eaf286a8d65d689e88e64e64e61c526