You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your feature request related to a problem? Please describe.
When running audit system on workstation with fewer logical iptables like drop input everything, allow all out, allow in established returns, it does not meet the required limit of 5 iptables or more. While this config is robust for workstations and weak on servers it makes workstation hardening complex for no reason.
Describe the solution you'd like
Identify if lynis running server or workstation/desktop on os and lower the iptables minimum count.
Leveraging different scoring for desktop vs server images could provide a more realistic effort to workstation hardening. Same relates to other checks not just iptables.
Required changes
IPTables count.
Additional context
This is an example of the iptables in place. iptables --list
Is your feature request related to a problem? Please describe.
When running
audit system
on workstation with fewer logical iptables like drop input everything, allow all out, allow in established returns, it does not meet the required limit of 5 iptables or more. While this config is robust for workstations and weak on servers it makes workstation hardening complex for no reason.Describe the solution you'd like
Identify if lynis running server or workstation/desktop on os and lower the iptables minimum count.
Leveraging different scoring for desktop vs server images could provide a more realistic effort to workstation hardening. Same relates to other checks not just iptables.
Required changes
IPTables count.
Additional context
This is an example of the iptables in place.
iptables --list
The text was updated successfully, but these errors were encountered: