3.4.2.2 Ensure iptables is not enabled - disabled

Information

IPtables is an application that allows a system administrator to configure the IPv4 and IPv6 tables, chains and rules provided by the Linux kernel firewall.
IPtables is installed as a dependency with firewalld.
Rationale:
Running firewalld and IPtables concurrently may lead to conflict, therefore IPtables should be stopped and masked when using firewalld.

Solution

Run the following command to stop and mask iptables
systemctl --now mask iptables

See Also

https://workbench.cisecurity.org/files/2485

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: 645f75d44b6cd1295419a2d3f799533680a20bda98bccfa81dff54045e23f0d5