4.10.1 Ensure ICMP Router Discovery is disabled

Information

ICMP Router Discovery should not be used.

Rationale:

ICMP Router Discovery provides details of routers attached to a broadcast or multicast segment in response to Router Solicitation messages from hosts or in the form of a period Router Advertisement.

These messages may provide an attacker attached to the segment with a clearer picture of network environment and also increases the attack surface of the JUNOS device. As the feature is rarely used, ICMP Router Discovery should only be configured on networks where a specific requirement exists for its use.

Solution

If you have configured ICMP Router Discovery and do not require it, you can disable it by issuing the following command from the [edit protocols router-discovery] hierarchy:

[edit protocols router-discovery]
user@host#set disable

Default Value:

ICMP Router Discovery is disabled by default.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Juniper

Control ID: 6ec45875cc87c22bb15db74e11c3ddcbff98edfe7ad0c47cbe8ada080b09f2c1