4.1.2 Ensure firewalld.service state is configured

Information

firewalld.service is a firewall service daemon that provides a dynamic, customizable firewall with a D-Bus interface.

firewalld.service must be active to enforce rules configured through FirewallD. firewalld.service must be enabled to start automatically after a system reboot.

Solution

Run the following commands to unmask, enable, and start firewalld.service :

# systemctl unmask firewalld.service
# systemctl --now enable firewalld.service

Note: On some systems SELinux may need to be placed into permissive mode to start firewalld.service . On these systems, SELinux should be placed in permissive mode, start firewalld.service and then put SELinux back into enforcing more.

See Also

https://workbench.cisecurity.org/benchmarks/25279

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 802f6bedb3229c5f9705a9c4da20f0394f2846b54219dbd3c36d9d43ade8e589