4.1.2 Ensure firewalld backend is configured

Information

The FirewallBackend option selects the firewall backend implementation.

Choices are:

- nftables (default)
- iptables (iptables, ip6tables, ebtables and ipset)

IPTables are deprecated.

Solution

Edit the file /etc/firewalld/firewalld.conf and add or modify the following line:

FirewallBackend=nftables

Impact:

Verifying the proper backend configuration insures the critical functionality of the firewall.

See Also

https://workbench.cisecurity.org/benchmarks/24164

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 5fa5f54343f61d53da880d4bb25542df2ebdd226011c4972a5be65e0c3e9c184