4.2.5 Ensure firewalld service is enabled and running

Information

firewalld.service enables the enforcement of firewall rules configured through firewalld

SUSE Linux Enterprise Server 15 GA introduces firewalld as the new default software firewall, replacing SuSEfirewall2

Solution

Run the following command to unmask firewalld

# systemctl unmask firewalld

Run the following command to enable and start firewalld

# systemctl --now enable firewalld

Impact:

Changing firewall settings while connected over network can result in being locked out of the system.

See Also

https://workbench.cisecurity.org/benchmarks/20333

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 899be0f1e299a0307eb0e6684ecef81b481bcf9a3e5f79c3a38d99bc6715b07d