4.2.7 Enable RFC-recommended Source Route Validation 'net.ipv4.conf.default.rp_filter = 1'

Information

Configuration Level : Level-II

Solution

Set the net.ipv4.conf.all.rp_filter and net.ipv4.conf.default.rp_filter parameters to 1 in /etc/sysctl.conf:
net.ipv4.conf.all.rp_filter=1
net.ipv4.conf.default.rp_filter=1

Modify active kernel parameters to match:
/sbin/sysctl -w net.ipv4.conf.all.rp_filter=1
/sbin/sysctl -w net.ipv4.conf.default.rp_filter=1
/sbin/sysctl -w net.ipv4.route.flush=1

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-6, 800-53|SC-7(12), CCE|CCE-3840-6, CCE|CCE-4080-8, CSCv6|9.2

Plugin: Unix

Control ID: 2dd9a00f51f681a9c0170d0309b218c95f21aa79ceb470b623d6b0f237891c94