4.1.3 Ensure firewalld.service is configured

Information

firewalld.service is a firewall service daemon that provides a dynamic, customizable firewall with a D-Bus interface.

firewalld.service must be active to enforce rules configured through FirewallD. firewalld.service must be enabled to start automatically after a system reboot.

Solution

Run the following commands to unmask, enable, and start firewalld.service :

# systemctl unmask firewalld.service
# systemctl --now enable firewalld.service

See Also

https://workbench.cisecurity.org/benchmarks/24164

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 48ff93691c6844ed168fca74d604603c7288bfc72ecd25ac61d3bf5cb6d50608