3.5.1.2 Ensure nftables is not installed or stopped and masked - nftables masked

Information

nftables is a subsystem of the Linux kernel providing filtering and classification of network packets/datagrams/frames and is the successor to iptables.

Notes:

Support for using nftables as the back-end for firewalld was added in release v0.6.0. In Fedora 19 Linux derivatives, firewalld utilizes iptables as it's back-end by default.

firewalld may be configured as the front-end to nftables. If this case, nftables should be stopped and masked instead of removed.

Rationale:

Running both firewalld and nftables may lead to conflict.

Solution

Run the following command to remove nftables:

# zypper remove nftables

OR
Run the following command to stop and mask nftables:

systemctl --now mask nftables

See Also

https://workbench.cisecurity.org/files/2854

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1, CSCv7|9.4

Plugin: Unix

Control ID: 03b3cac43cc38df7527c9878a44518707eacd9cef957b19196a9c6d6bed548a7