Inspect and Activate Default Rules
An XCCDF Group
Description
View the currently-enforced iptables
rules by running
the command:
$ sudo iptables -nL --line-numbersThe command is analogous for
ip6tables
.
If the firewall does not appear to be active (i.e., no rules appear), activate it and ensure that it starts at boot by issuing the following commands (and analogously for
ip6tables
):
$ sudo service iptables restartThe default iptables rules are:
Chain INPUT (policy ACCEPT) num target prot opt source destination 1 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED 2 ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 3 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 4 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:22 5 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited Chain FORWARD (policy ACCEPT) num target prot opt source destination 1 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited Chain OUTPUT (policy ACCEPT) num target prot opt source destinationThe
ip6tables
default rules are essentially the same.
- ID
- xccdf_org.ssgproject.content_group_iptables_activation
- Child Items
- Updated