3.12 Set Strict Multihoming - persistent ipv6 = 0

Information

These settings control whether a packet arriving on a non-forwarding interface can be accepted for an IP address that is not explicitly configured on that interface.

Enable this setting for systems that have interfaces that cross strict networking domains (for example, a firewall or a VPN node).

Solution

To enforce this setting for IPv4 packets, use the command:
# ipadm set-prop -p _strict_dst_multihoming=1 ipv4

To enforce this setting for IPv6 packets, use the command:
# ipadm set-prop -p _strict_dst_multihoming=1 ipv6

See Also

https://workbench.cisecurity.org/files/611

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv6|9.2

Plugin: Unix

Control ID: 3fb859afea169c10998cd87a1f103e5db8c262d65651c25f742454a5fb648c76