SV-219554r603263_rule
V-219554
SRG-OS-000480
OL6-00-000120
CAT II
10
To set the default policy to DROP (instead of ACCEPT) for the built-in INPUT chain which processes incoming packets, add or correct the following line in "/etc/sysconfig/iptables":
:INPUT DROP [0:0]
Inspect the file "/etc/sysconfig/iptables" to determine the default policy for the INPUT chain. It should be set to DROP.
# grep ":INPUT" /etc/sysconfig/iptables
If the default policy for the INPUT chain is not set to DROP, this is a finding.
V-219554
False
OL6-00-000120
Inspect the file "/etc/sysconfig/iptables" to determine the default policy for the INPUT chain. It should be set to DROP.
# grep ":INPUT" /etc/sysconfig/iptables
If the default policy for the INPUT chain is not set to DROP, this is a finding.
M
2928