3.4.4.1.3 Ensure Uncomplicated Firewall (UFW) is not installed or stopped and masked

Information

Uncomplicated Firewall (UFW) is a program for managing a netfilter firewall designed to be easy to use.

Uses a command-line interface consisting of a small number of simple commands

Uses iptables for configuration

Rationale:

Running iptables.persistent with ufw.service may lead to conflict and unexpected results.

Solution

Run the following command to remove firewalld

# apt purge ufw

OR
Run the following command to stop and mask firewalld

# systemctl --now mask ufw

See Also

https://workbench.cisecurity.org/files/2970

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv7|9.4

Plugin: Unix

Control ID: 31bc6ec5556dd359fd64c77c49f400f65119d6363658067e02fe22cb93428349