4.1.2 Ensure firewalld backend is configured

Information

The FirewallBackend option selects the firewall backend implementation.

Choices are:

- nftables (default)
- iptables (iptables, ip6tables, ebtables and ipset)

IPTables are deprecated.

Solution

Edit the file /etc/firewalld/firewalld.conf and add or modify the following line:

FirewallBackend=nftables

Impact:

Verifying the proper backend configuration insures the critical functionality of the firewall.

See Also

https://workbench.cisecurity.org/benchmarks/24008

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: ad52afdb966b2394b5e739b85d38465bb26279546bc43ae726900b308e6704c3