4.1.2 Ensure firewalld backend is configured

Information

The FirewallBackend option selects the firewall backend implementation.

Choices are:

- nftables (default)
- iptables (iptables, ip6tables, ebtables and ipset)

IPTables are deprecated.

Solution

Edit the file /etc/firewalld/firewalld.conf and add or modify the following line:

FirewallBackend=nftables

Impact:

Verifying the proper backend configuration insures the critical functionality of the firewall.

See Also

https://workbench.cisecurity.org/benchmarks/24010

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: d289fb6c2a9d20a146e1941abf980b8dca4e6d1aef71bc19de240925ff7bb917