GEN008540 - The systems local firewall must implement a deny-all, allow-by-exception policy.

Information

A local firewall protects the system from exposing unnecessary or undocumented network services to the local enclave. If a system within the enclave is compromised, firewall protection on an individual system continues to protect it from attack.

Solution

Edit '/etc/sysconfig/iptables' and add a default deny rule.

An example of a default deny rule:
-A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited

Restart the iptable service.
# service iptables restart

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(1), 800-53|SC-7(5), CAT|II, CCI|CCI-001109, CCI|CCI-002314, Rule-ID|SV-218718r603259_rule, STIG-ID|GEN008540, STIG-Legacy|SV-63141, STIG-Legacy|V-22583, Vuln-ID|V-218718

Plugin: Unix

Control ID: 70c7c3f2d769f56dc3c597f615fbea08165086123e968af93acaf6db018d53de