7.7 Ensure Firewall is active - iptables-persistent run level 5

Information

IPtables is an application that allows a system administrator to configure the IPv4 tables, chains and rules provided by the Linux kernel firewall. The iptables-persistent package in Debian provides one way to ensure iptables rules are reapplied on reboot. Note: the audit and remediation included provide instructions for using iptables-persistent to reapply iptables rules. Other methods are available which may be in use in your environment and may conflict with these steps. IPtables provides extra protection for the Linux system by limiting communications in and out of the box to specific IPv4 addresses and ports.

Solution

Install the iptables and iptables-persistent packages- # apt-get install iptables iptables-persistent Enable the iptables-persistent service- # update-rc.d iptables-persistent enable

See Also

https://workbench.cisecurity.org/files/85

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: Unix

Control ID: 98892dee92659ead3a1cb9c6dd9725bb42048b9e6f6bc54b2ce81987cb1dd4ea