SV-268078r1130947_rule
V-268078
SRG-OS-000298-GPOS-00116
ANIX-00-000010
CAT II
10
Update the NixOS config, typically stored either in /etc/nixos/configuration.nix or /etc/nixos/flake.nix, to enforce firewall rules by adding the following configuration settings:
networking.firewall.enable = true;
Rebuild and switch to the new NixOS configuration:
$ sudo nixos-rebuild switch
Verify NixOS has the network firewall enabled with the following command:
$ sudo iptables -L | grep nixos-fw-log-refuse
nixos-fw-log-refuse all -- anywhere anywhere
Verify the firewall panic tools are present:
$ which firewall-panic
/run/current-system/sw/bin/firewall-panic
$ which firewall-panic-off
/run/current-system/sw/bin/firewall-panic-off
If the "nixos-fw-log-refuse all -- anywhere anywhere" firewall rule is not present and the firewall panic commands are not found, this is a finding.
V-268078
False
ANIX-00-000010
Verify NixOS has the network firewall enabled with the following command:
$ sudo iptables -L | grep nixos-fw-log-refuse
nixos-fw-log-refuse all -- anywhere anywhere
Verify the firewall panic tools are present:
$ which firewall-panic
/run/current-system/sw/bin/firewall-panic
$ which firewall-panic-off
/run/current-system/sw/bin/firewall-panic-off
If the "nixos-fw-log-refuse all -- anywhere anywhere" firewall rule is not present and the firewall panic commands are not found, this is a finding.
M
5658