3.3.8 ipsrcrouteforward

Information

The ipsrcrouteforward parameter determines whether or not the system forwards IPV4 source-routed packets.

Rationale:

The ipsrcrouteforward will be set to 0, to prevent source-routed packets being forwarded by the system. This would prevent a hacker from using source-routed packets to bridge an external facing server to an internal LAN, possibly even through a firewall.

Solution

In /etc/tunables/nextboot, add the ipsrcrouteforward entry:

no -p -o ipsrcrouteforward=0

This makes the change permanent by adding the entry into /etc/tunables/nextboot

Default Value:

1

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: Unix

Control ID: 8785ff55b8ce506dab5e221b55012e0d3f2c19f5bbd1fab3e21e4d455c3ca801