GEN007700 - The IPv6 protocol handler must not be bound to the network stack unless needed.

Information

IPv6 is the next version of the Internet protocol. Binding this protocol to the network stack increases the attack surface of the host.

Solution

Unbind the IPv6 protocol handler from the network stack.
Edit /etc/rc.tcpip and comment out autoconf6 to prevent IPv6 from auto starting.
Unconfigure IPv6 addresses from interfaces not used with smit.
#smit chinet6

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4, CAT|II, CCI|CCI-001551, Rule-ID|SV-38918r1_rule, STIG-ID|GEN007700, Vuln-ID|V-22541

Plugin: Unix

Control ID: 15b7d1220de7dda183de0e8c71c8c8f11c6b59691ac67f1832d0bd37ff47eedf