7.3.2 Disable IPv6 Redirect Acceptance - 'net.ipv6.conf.all.accept_redirects = 0'

Information

This setting prevents the system from accepting ICMP redirects. ICMP redirects tell the
system about alternate routes for sending traffic.

*Rationale*

It is recommended that systems not accept ICMP redirects as they could be tricked into
routing traffic to compromised machines. Setting hard routes within the system (usually a
single default route to a trusted router) protects the system from bad routes.

Solution

Set the net.ipv6.conf.all.accept_redirects and net.ipv6.conf.default.accept_redirects
parameters to 0 in /etc/sysctl.conf-net.ipv6.conf.all.accept_redirects=0
net.ipv6.conf.default.accept_redirects=0

Modify active kernel parameters to match-
# /sbin/sysctl -w net.ipv6.conf.all.accept_redirects=0
# /sbin/sysctl -w net.ipv6.conf.default.accept_redirects=0
# /sbin/sysctl -w net.ipv6.route.flush=1

See Also

https://workbench.cisecurity.org/files/91

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv6|9.2

Plugin: Unix

Control ID: 2eb421bfccb7c6524d037362ea713e0b2f84520b35de9cb210a3b651254ce0ec