SV-219588r603263_rule
V-219588
SRG-OS-000480
OL6-00-000523
CAT II
10
To set the default policy to DROP (instead of ACCEPT) for the built-in INPUT chain which processes incoming packets, add or correct the following line in "/etc/sysconfig/ip6tables":
:INPUT DROP [0:0]
Restart the IPv6 firewall:
# service ip6tables restart
If IPv6 is disabled, this is not applicable.
Inspect the file "/etc/sysconfig/ip6tables" to determine the default policy for the INPUT chain. It should be set to DROP:
# grep ":INPUT" /etc/sysconfig/ip6tables
If the default policy for the INPUT chain is not set to DROP, this is a finding.
V-219588
False
OL6-00-000523
If IPv6 is disabled, this is not applicable.
Inspect the file "/etc/sysconfig/ip6tables" to determine the default policy for the INPUT chain. It should be set to DROP:
# grep ":INPUT" /etc/sysconfig/ip6tables
If the default policy for the INPUT chain is not set to DROP, this is a finding.
M
2928