2.17 Bind swarm services to a specific host interface

Information

https://docs.docker.com/engine/reference/commandline/swarm_init/#/listen-
addr-value
2.https://docs.docker.com/engine/swarm/admin_guide/#/recover-from-disaster
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Remediation of this requires re-initialization of the swarm specifying a specific interface
for the --listen-addr parameter.Impact-NoneDefault Value-By default, docker swarm services listen on all available host interfaces.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(13)

Plugin: Unix

Control ID: a15f4964e7a29a0825c8e0722e8d1d6e818de8854ca89731450112250f8ebc8c