6.5.3 Ensure ICMP Source-Quench is Set to Disabled

Information

ICMP Source Quench messages should be ignored.

Rationale:
ICMP Source Quench messages are intended to allow a host to request that a peer with which it is communicating slows down the transmission of new data because the host is being overwhelmed.
Several recorded vulnerabilities have shown how Source Quench messages may be abused by an attacker to create a DoS attack, causing the router to slow down transmission of data to one, several or all destinations. Due to these vulnerabilities, and the general ineffectiveness of Source Quench for congestion control, RFC6633 deprecated its use and ICMP Source Quench should be disabled.

Solution

Configure the JUNOS Device to ignore ICMP source-quench messages by issuing the following command from the [edit system internet-options] hierarchy.
[edit system internet-options]
user@host#set no-source-quench

Impact:
ICMP Source Quench is deprecated and there is no valid reason for ICMP Source Quench to be present on a modern network.

Default Value:
By default the router does not ignore ICMP Source Quench messages.

See Also

https://workbench.cisecurity.org/files/2278

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5, CSCv7|11

Plugin: Juniper

Control ID: 7589e7aa42c86d5e1775cf5781b97cfcf54e3a9ae8c4a3843c20710bedeed74e