3.5.1.6 Ensure network interfaces are assigned to appropriate zone

Information

firewall zones define the trust level of network connections or interfaces.

A network interface not assigned to the appropriate zone can allow unexpected or undesired network traffic to be accepted on the interface.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Run the following command to assign an interface to the approprate zone.

# firewall-cmd --zone=<Zone NAME> --change-interface=<INTERFACE NAME>

Example:

# firewall-cmd --zone=customezone --change-interface=eth0

Impact:

Changing firewall settings while connected over network can result in being locked out of the system.

See Also

https://workbench.cisecurity.org/benchmarks/8415

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: d781cf824ca469a9bd6a041239bc48967fe8da26ecbc4fa014d26ad307e4964c