3.12 Set Strict Multihoming - persistent ipv6 = 1

Information

These settings control whether a packet arriving on a non-forwarding interface can be
accepted for an IP address that is not explicitly configured on that interface.

Enable this setting for systems that have interfaces that cross strict networking domains
(for example, a firewall or a VPN node).

Solution

To enforce this setting for IPv4 packets, use the command-# ipadm set-prop -p _strict_dst_multihoming=1 ipv4To enforce this setting for IPv6 packets, use the command-# ipadm set-prop -p _strict_dst_multihoming=1 ipv6

See Also

https://workbench.cisecurity.org/files/616

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv6|9.2

Plugin: Unix

Control ID: 3633fe24e8bdd5d20813ee8fb55a37a156c607370fffc461dfbef3b61ddf1b1d