3.6 Disable Directed Broadcast Packet Forwarding

Information

This setting controls whether Solaris forwards broadcast packets for a specific network if it is directly connected to the machine.

Rationale:

Keep this parameter disabled to prevent denial of service attacks.

Solution

To enforce this setting, run the following command:

# ipadm set-prop -p _forward_directed_broadcasts=0 ip

See Also

https://workbench.cisecurity.org/benchmarks/4777

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.4

Plugin: Unix

Control ID: d75c0d5f875dea74e8671b9833e79afa8d7a87dc4697b84d2c0cedfcf6e83a15