3.13 Disable ICMP Redirect Messages - current ipv4 = 0

Information

These setting controls whether Solaris sends ICMPv4 and ICMPv6 redirect messages.

A malicious user can exploit the ability of the system to send ICMP redirects by continually sending packets to the system, forcing the system to respond with ICMP redirect messages, resulting in an adverse impact on the CPU performance of the system.

Solution

To enforce this setting for IPv4 packets, use the command:
# ipadm set-prop -p _send_redirects=0 ipv4

To enforce this setting for IPv6 packets, use the command:
# ipadm set-prop -p _send_redirects=0 ipv6

See Also

https://workbench.cisecurity.org/files/612

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv6|9.2

Plugin: Unix

Control ID: feeb416f01161a8b12fd75808381ca1cb8deeb52963063cc4053ea728ca365ee