3.5.2.1 Ensure nftables is installed

Information

nftables provides a new in-kernel packet classification framework that is based on a network-specific Virtual Machine (VM) and a new nft userspace command line tool. nftables reuses the existing Netfilter subsystems such as the existing hook infrastructure, the connection tracking system, NAT, userspace queuing and logging subsystem.

Notes:

nftables is available in Linux kernel 3.13 and newer

Only one firewall utility should be installed and configured

Changing firewall settings while connected over the network can result in being locked out of the system

Rationale:

nftables is a subsystem of the Linux kernel that can protect against threats originating from within a corporate network to include malicious mobile code and poorly configured software on a host.

Solution

Run the following command to install nftables:

# apt install nftables

See Also

https://workbench.cisecurity.org/files/3219

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv7|9.4

Plugin: Unix

Control ID: 69da363c5e3ea0b760749bb3c9ae581555eb969c03bdcebf9fe551cbc76858a2