-
Notifications
You must be signed in to change notification settings - Fork 67
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Rule 3.3.4: if ufw is used, then the rule is overwritten #69
Comments
hi @CFoltin Thank you for raising this issue. Feedback like this helps us to improve the content we supply. I believe if you have set IPT_SYSCTL= /etc/sysctl.conf If you are using UFW and not changed the sysctl import file, still want it logged you need to add that line to the /etc/ufw/sysctl.conf as you have mentioned. Reading into this it could be quite a bespoke setting and not actually directly listed as part of a requirement for CIS unless the options above and ufw import file not changed and the settings in the ufw file override and turn it off. I believe what would be required is. If the file /etc/ufw/sysctl.conf exists and contains *log_martians=0 then change that as well even if not using ufw? or Do we then change the /etc/default/ufw to be IPT_SYSCTL=/etc/sysctl.conf and add a comment? Any thoughts? thanks uk-bolly |
hi @CFoltin Thank you again for raising this issue. This has now been merged into the devel branch. Aiming to put this into main if all is well in the next couple of weeks. many thanks again uk-bolly |
See
UBUNTU20-CIS/tasks/section_3/cis_3.3.x.yml
Line 104 in a1f61e2
Use the additional rule (maybe an additional when for ufw check is missing...)
The text was updated successfully, but these errors were encountered: