From 51cd810d9a5ed123d6ec84d20f326f7b9af232de Mon Sep 17 00:00:00 2001 From: wqian Date: Mon, 22 Jul 2024 09:52:56 +0100 Subject: [PATCH 1/2] Correct the platform detect As the cis rule indicates: remove iptables-persistent if ufw is installed --- .../package_iptables-persistent_removed/rule.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/linux_os/guide/system/network/network-iptables/package_iptables-persistent_removed/rule.yml b/linux_os/guide/system/network/network-iptables/package_iptables-persistent_removed/rule.yml index fcd1ccfc61a..78a0a68cc03 100644 --- a/linux_os/guide/system/network/network-iptables/package_iptables-persistent_removed/rule.yml +++ b/linux_os/guide/system/network/network-iptables/package_iptables-persistent_removed/rule.yml @@ -12,7 +12,7 @@ rationale: |- severity: medium -platform: package[iptables] +platform: package[ufw] references: cis@ubuntu2004: 3.5.1.2 From f67338ca3fe4c8256cc9cd8ca4d0c4fe5973fc71 Mon Sep 17 00:00:00 2001 From: wqian Date: Mon, 22 Jul 2024 11:41:11 +0100 Subject: [PATCH 2/2] Add rule into components --- components/ufw.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/components/ufw.yml b/components/ufw.yml index df36a047093..3ceaeeed906 100644 --- a/components/ufw.yml +++ b/components/ufw.yml @@ -13,3 +13,4 @@ rules: - ufw_only_required_services - ufw_rate_limit - ufw_rules_for_open_ports +- package_iptables-persistent_removed