2.3 Allow Docker to make changes to iptables

Information

https://docs.docker.com/v1.8/articles/networking/

Solution

Do not run the Docker daemon with '--iptables=false' parameter.For example, do not start the Docker daemon as below-
dockerdaemon --iptables=false
Impact-
None.
Default Value-
By default, 'iptables' is set to 'true'.

See Also

https://workbench.cisecurity.org/files/516

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: Unix

Control ID: ec4e7daf41488893ce613d9f2a6bba4e634d919d03451c1f57dbc96a354a4d2e