4.2.3 Disable Secure ICMP Redirect Acceptance 'net.ipv4.conf.all.secure_redirects = 0'

Information

Configuration Level : Level-II

Solution

Set the net.ipv4.conf.all.secure_redirects and net.ipv4.conf.default.secure_redirects parameters to 0 in /etc/sysctl.conf:
net.ipv4.conf.all.secure_redirects=0
net.ipv4.conf.default.secure_redirects=0

Modify active kernel parameters to match:
/sbin/sysctl -w net.ipv4.conf.all.secure_redirects=0
/sbin/sysctl -w net.ipv4.conf.default.sec

See Also

https://workbench.cisecurity.org/files/214

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-6, 800-53|SC-7(12), CCE|CCE-3339-9, CCE|CCE-3472-8, CSCv6|9.2

Plugin: Unix

Control ID: e3d94b6581bb5d8e1c111acd13eb974a653838dc6961c7538bd021071048903c