Cis Ubuntu1604 V200 3 5 3 1 2

Ensure nftables is not installed with iptables

cyberstrikeus Updated

File contents

CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 - Control 3.5.3.1.2

Profile

  • Level: Level 1 - Server, Level 1 - Workstation
  • Assessment Status: Automated

Description

nftables is a subsystem of the Linux kernel providing filtering and classification of network packets/datagrams/frames and is the successor to iptables.

Rationale

Running both iptables and nftables may lead to conflict.

Audit Procedure

Command Line

Run the following command to verify that nftables is not installed:

dpkg -s nftables

Expected Result

dpkg-query: package 'nftables' is not installed

Remediation

Command Line

Run the following command to remove nftables:

apt purge nftables

References

None

CIS Controls

Version 7

9.4 Apply Host-based Firewalls or Port Filtering - Apply host-based firewalls or port filtering tools on end systems, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-16-04-lts-benchmark-v2/cis-ubuntu1604-v200-3-5-3-1-2 commit 2fcf7be332

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1604-v200-3-5-3-1-2