3.5.1.2 Ensure nftables is not installed or stopped and masked

Information

nftables is a subsystem of the Linux kernel providing filtering and classification of network packets/datagrams/frames and is the successor to iptables.

Notes:

-

Support for using nftables as the back-end for firewalld was added in release v0.6.0. In Fedora 19 Linux derivatives, firewalld utilizes iptables as it's back-end by default.

-

firewalld may be configured as the front-end to nftables. If this case, nftables should be stopped and masked instead of removed.

Running both firewalld and nftables may lead to conflict.

Solution

Run the following command to remove nftables :

# zypper remove nftables

OR

Run the following command to stop and mask nftables :

systemctl --now mask nftables

See Also

https://workbench.cisecurity.org/files/3682

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|CM-6, 800-53|CM-7, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: c625c3adc9d2435065b54554a5e7712926ca72a678ea94d89b9fa177336d39fa