diff --git a/controls/cis_sle15.yml b/controls/cis_sle15.yml index 29ae963512b..c6b8f2ffc28 100644 --- a/controls/cis_sle15.yml +++ b/controls/cis_sle15.yml @@ -1018,7 +1018,9 @@ controls: levels: - l1_server - l1_workstation - status: manual # rule is missing + status: automated + rules: + - package_firewalld_removed - id: 3.5.2.3 title: Ensure iptables are flushed (Manual) @@ -1100,7 +1102,9 @@ controls: levels: - l1_server - l1_workstation - status: manual # rule is missing + status: automated + rules: + - package_firewalld_removed - id: 3.5.3.2.1 title: Ensure default deny firewall policy (Automated) diff --git a/linux_os/guide/system/network/network-firewalld/firewalld_deactivation/package_firewalld_removed/rule.yml b/linux_os/guide/system/network/network-firewalld/firewalld_deactivation/package_firewalld_removed/rule.yml new file mode 100644 index 00000000000..304d8bb6bea --- /dev/null +++ b/linux_os/guide/system/network/network-firewalld/firewalld_deactivation/package_firewalld_removed/rule.yml @@ -0,0 +1,34 @@ +documentation_complete: true + +prodtype: sle15 + +title: 'Uninstall firewalld Package' + +description: |- + firewalld (Dynamic Firewall Manager) provides a dynamically managed firewall with + support for network/firewall “zones” to assign a level of trust to a network and its + associated connections, interfaces or sources. It has support for IPv4, IPv6, Ethernet + bridges and also for IPSet firewall settings. There is a separation of the runtime and + permanent configuration options. + {{{ describe_package_remove(package="firewalld") }}} + +rationale: |- + Running both nftables.service and firewalld.service may lead to conflict and + unexpected results. + +severity: medium + +identifiers: + cce@sle15: CCE-92471-2 + +references: + cis@sle15: 3.5.2.2,3.5.3.1.3 + +{{{ complete_ocil_entry_package(package="firewalld") }}} + +fixtext: '{{{ fixtext_package_removed("firewalld") }}}' + +template: + name: package_removed + vars: + pkgname: firewalld diff --git a/shared/references/cce-sle15-avail.txt b/shared/references/cce-sle15-avail.txt index 052286896b2..373f7311b36 100644 --- a/shared/references/cce-sle15-avail.txt +++ b/shared/references/cce-sle15-avail.txt @@ -53,7 +53,6 @@ CCE-92467-0 CCE-92468-8 CCE-92469-6 CCE-92470-4 -CCE-92471-2 CCE-92472-0 CCE-92473-8 CCE-92474-6