3.3.6 ipignoreredirects

Information

The ipignoreredirects parameter determines whether or not the system will process IP redirects.

Rationale:

The ipignoreredirects will be set to 1, to prevent IP re-directs being processed by the system.

Solution

In /etc/tunables/nextboot, add the ipignoreredirects entry:

no -p -o ipignoreredirects=1

This makes the change permanent by adding the entry into /etc/tunables/nextboot

Default Value:

0

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: Unix

Control ID: 524f71a2f71c5cca2e601e89b7192b12298c2aa5c7c8a79fd2b3d772cfbdcd80