4.4.2 Disable IPv6 - options ipv6 disable=1

Information

Although IPv6 has many advantages over IPv4, few organizations have implemented IPv6.

Rationale:

If IPv6 is not to be used, it is recommended that the driver not be installed. While use of IPv6 is not a security issue, it will cause operational slowness as packets are tried via IPv6, when there are no recipients. In addition, disabling unneeded functionality reduces the potential attack surface.

Solution

Run the following command:

# echo 'options ipv6 'disable=1'' >> /etc/modprobe.conf

Default Value:

OS Default: N/A

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1, CSCv6|9.2, CSCv7|9.2

Plugin: Unix

Control ID: 33e4a642a8d8ad1e4450133b6a973ec1310dbd6052996424b948a0e6360114fb