3.3.10 ipsrcroutesend

Information

The ipsrcroutesend parameter determines whether or not the system can send source-routed packets.

Rationale:

The ipsrcroutesend parameter will be set to 0, to ensure that any local applications cannot send source routed packets.

Solution

In /etc/tunables/nextboot, add the ipsrcroutesend entry:

no -p -o ipsrcroutesend=0

This makes the change permanent by adding the entry into /etc/tunables/nextboot

Default Value:

1

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: Unix

Control ID: 54b459d9131d50fe120a9c0957ca3e3c948f59b65a548df2684033bfce2d5296