4.810 - The system access control program must be configured to grant or deny system access to specific hosts and services.

Information

If the systems access control program is not configured with appropriate rules for allowing and denying access to system network resources, services may be accessible to unauthorized hosts.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

If 'firewalld' is installed and active on the system, configure rules for allowing specific services and hosts.

If 'firewalld' is not 'active', enable 'tcpwrappers' by configuring '/etc/hosts.allow' and '/etc/hosts.deny' to allow or deny access to specific hosts.

See Also

https://docs.fedoraproject.org/f28/system-administrators-guide/index.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CAT|II, CCI|CCI-000366

Plugin: Unix

Control ID: 38d01d58c067edd4cee8a6ec41d33d94ebc006bbd1d3cd06e6cd283ca889e661