4.2.6 ipignoreredirects

Information

The ipignoreredirects parameter determines whether or not the system will process IP redirects.

Rationale:

The ipignoreredirects will be set to 1, to prevent IP re-directs being processed by the system.

Solution

In /etc/tunables/nextboot, add the ipignoreredirects entry:

no -p -o ipignoreredirects=1

This makes the change permanent by adding the entry into /etc/tunables/nextboot

Default Value:

0

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: Unix

Control ID: 4b2c51de94726d40c3a9c09da0edcde39a0290859740775dd34b110bafd2f6a6