[Forgot Password]
Login  Register Subscribe

25354

 
 

132804

 
 

134729

 
 

909

 
 

109403

 
 

153

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-92058-7

Platform: Amazon LinuxDate: (C)2018-10-29   (M)2019-09-10



Set Default ip6tables Policy for Incoming Packets To set the default policy to DROP (instead of ACCEPT) for the built-in INPUT chain which processes incoming packets, add or correct the following line in '/etc/sysconfig/ip6tables': ':INPUT DROP [0:0]' If changes were required, reload the ip6tables rules: '$ sudo service ip6tables reload'


Parameter:


Technical Mechanism: In 'ip6tables', the default policy is applied only after all the applicable rules in the table are examined for a match. Setting the default policy to 'DROP' implements proper design for a firewall, i.e. any packets which are not explicitly permitted should not be accepted. Fix: No Remediation Info

References:

Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:48245
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:49007
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:48245


OVAL    2
oval:org.secpod.oval:def:49007
oval:org.secpod.oval:def:48245
XCCDF    2
xccdf_org.secpod_benchmark_general_Amazon_Linux_AMI
xccdf_org.secpod_benchmark_general_Amazon_Linux_2

© SecPod Technologies