1.1.1.2.1.56 Set 'MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)'

Information

1.1.1.2.1.56 Set 'MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)' to 'Highest protection, source routing is completely disabled'

The registry value entry DisableIPSourceRouting was added to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\ registry key. The entry appears as MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing) in the SCE. IP source routing is a mechanism that allows the sender to determine the IP route that a datagram should take through the network. It is recommended to configure this setting to Not Defined for enterprise environments and to Highest Protection for high security environments to completely disable source routing. An attacker could use source routed packets to obscure their identity and location. Source routing allows a computer that sends a packet to specify the route that the packet takes.

Solution

To implement the recommended configuration state, set the following Group Policy setting to 2.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\MSS- (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)

Impact- If you configure this value to 2, all incoming source routed packets will be dropped.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CCE|CCE-3227-6, CSCv6|9.2

Plugin: Windows

Control ID: 19c03a6f2d30ad647953a0346d63adb5165ffefc6023bff35d43b13893280d84