4.2.7 ipsendredirects

Information

The ipsendredirects parameter determines whether or not the system forwards re-directed TCP/IP packets.

Rationale:

The ipsendredirects parameter will be set to 0, to ensure that redirected packets do not reach remote networks.

Solution

In /etc/tunables/nextboot, add the ipsendredirects entry:

no -p -o ipsendredirects=0

This makes the change permanent by adding the entry into/etc/tunables/nextboot

Default Value:

1

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12)

Plugin: Unix

Control ID: d2b858713fe67c423b84bbe3aff102fd0e1c26e7b6c99605cd26b245a91a2f45