3.3.3 Ensure IPv6 is disabled

Information

Although IPv6 has many advantages over IPv4, few organizations have implemented IPv6.

Rationale:

If IPv6 is not to be used, it is recommended that it be disabled to reduce the attack surface of the system.

Solution

Edit /boot/grub/menu.lst to include 'ipv6.disable=1' on all kernel lines.

See Also

https://workbench.cisecurity.org/files/3738

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.4

Plugin: Unix

Control ID: 76e1525cdc8cc3f8ced1581a88149b86230938f957b313bd454586cd312fa83c