4.2.3 Ensure iptables-persistent is not installed with ufw

Information

The iptables-persistent is a boot-time loader for netfilter rules, iptables plugin

Running both ufw and the services included in the iptables-persistent package may lead to conflict

Solution

Run the following command to remove the iptables-persistent package:

# apt purge iptables-persistent

See Also

https://workbench.cisecurity.org/benchmarks/21369

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: 80c2e4884c2b78f09439c37324589e5a185174ed4299831216e0081a447b0189