4.10.1 Ensure ICMP Router Discovery is disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

ICMP Router Discovery should not be used.

Rationale:
ICMP Router Discovery provides details of routers attached to a broadcast or multicast segment in response to Router Solicitation messages from hosts or in the form of a period Router Advertisement.
These messages may provide an attacker attached to the segment with a clearer picture of network environment and also increases the attack surface of the JUNOS device. As the feature is rarely used, ICMP Router Discovery should only be configured on networks where a specific requirement exists for its use.

Solution

If you have configured ICMP Router Discovery and do not require it, you can disable it by issuing the following command from the [edit protocols router-discovery] hierarchy:
[edit protocols router-discovery]
user@host#set disable

Default Value:
ICMP Router Discovery is disabled by default.

See Also

https://workbench.cisecurity.org/files/2278

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(16), CSCv7|9.2

Plugin: Juniper

Control ID: a9115bfd7758abcfb2bb646e7fe6ec4a72f27a04d48debdc0f74e30c287fbfbb