# Cis Ubuntu1804 V220 4 2 7

> Ensure sshd DisableForwarding is enabled

- Skill: `cyberstrikeus/cis-ubuntu1804-v220-4-2-7` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-ubuntu1804-v220-4-2-7`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-ubuntu1804-v220-4-2-7/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-ubuntu1804-v220-4-2-7

---


# CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 - Control 4.2.7

## Profile Applicability

- Level 2 - Server
- Level 2 - Workstation

## Description

`DisableForwarding` disables all forwarding features, including X11, ssh-agent, TCP and StreamLocal. This overrides all other forwarding-related options and can simplify restricted configurations.

## Rationale

Leaving port forwarding mechanisms enabled can expose the organization to security risks and back-channels. SSH includes a port-forwarding mechanism that enables tunneling of network protocols and allows for unauthorized communication to bypass firewall restrictions.

## Impact

SSH tunnels are widely used in many corporate environments. In some environments the applications themselves may have limited native support for security and may rely on SSH tunnels for encryption and security. Disabling SSH forwarding may impact these systems. Review the need for SSH forwarding before disabling it.

## Audit Procedure

### Command Line

Run the following command and verify the output:

```bash
sshd -T | grep -i disableforwarding
```

### Expected Result

```
disableforwarding yes
```

## Remediation

### Command Line

Edit the `/etc/ssh/sshd_config` file to set the parameter as follows:

```bash
DisableForwarding yes
```

## Default Value

DisableForwarding no

## References

1. NIST SP 800-53 Rev. 5: CM-7

## CIS Controls

v8 - 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software - Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.

v7 - 9.2 Ensure Only Approved Ports, Protocols, and Services Are Running.

## Profile Applicability

- Level 2 - Server
- Level 2 - Workstation

## Assessment Status

Automated

