3.6 Disable IPv6

Information

Although IPv6 has many advantages over IPv4, not all organizations have IPv6 or dual stack configurations implemented. If IPv6 or dual stack is not to be used, it is recommended that IPv6 be disabled to reduce the attack surface of the system.

Solution

Edit /etc/default/grub and add ipv6.disable=1 to the GRUB_CMDLINE_LINUX parameters: GRUB_CMDLINE_LINUX="ipv6.disable=1" Run the following command to update the grub2 configuration: # grub2-mkconfig –o /boot/grub2/grub.cfg

See Also

https://workbench.cisecurity.org/files/2518

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv7|9.2

Plugin: Unix

Control ID: 7f2b04bd8c5782fe5d4470e99bf9d9aaf4390d0bef5b03be241cd2fab4556a9d