4.1.2 Ensure firewalld backend is configured

Information

The FirewallBackend option selects the firewall backend implementation.

Choices are:

- nftables (default)
- iptables (iptables, ip6tables, ebtables and ipset)

IPTables are deprecated.

Solution

Edit the file /etc/firewalld/firewalld.conf and add or modify the following line:

FirewallBackend=nftables

Impact:

Verifying the proper backend configuration insures the critical functionality of the firewall.

See Also

https://workbench.cisecurity.org/benchmarks/23598

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: cc6483e7d837853f0479d9b193b6a848fbda5bcfb82e69bb8d89f4b7912ebe68