3.4.2.3 Ensure nftables is not enabled - inactive

Information

nftables is a subsystem of the Linux kernel providing filtering and classification of network packets/datagrams/frames and is the successor to iptables.
nftables are installed as a dependency with firewalld.
Rationale:
Running firewalld and nftables concurrently may lead to conflict, therefore nftables should be stopped and masked when using firewalld.

Solution

Run the following command to mask and stop nftables
systemctl --now mask nftables
Notes:
firewalld is dependent on nftables. nftables should be stopped and disabled.

See Also

https://workbench.cisecurity.org/files/2485

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 5a4d6b7d89d883cdd87bcf76e1d6a36e5f3aa3568401df254bc73e28176e33db