3.3.3 Ensure IPv6 is disabled

Information

Although IPv6 has many advantages over IPv4, few organizations have implemented IPv6. If IPv6 is not to be used, it is recommended that it be disabled to reduce the attack surface of the system.

Solution

Edit /etc/default/grub and add ' ipv6.disable=1' to GRUB_CMDLINE_LINUX: GRUB_CMDLINE_LINUX='ipv6.disable=1' Run the following command to update the grub2 configuration: # grub2-mkconfig > /boot/grub2/grub.cfg

See Also

https://workbench.cisecurity.org/files/1865

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(9)

Plugin: Unix

Control ID: 871b904a1b66fe394df7c96bbe68b8755e2499ff22a1e7e0a83aac62d628c4ef