GEN003602 - The system must not process ICMP timestamp requests.

Information

The processing of Internet Control Message Protocol (ICMP) timestamp requests increases the attack surface of the system.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Use SMIT or genfilt commands to configure the system firewall to block ICMP packet types 13, and 14.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4, CAT|III, CCI|CCI-001551, Rule-ID|SV-38866r1_rule, STIG-ID|GEN003602, Vuln-ID|V-22409

Plugin: Unix

Control ID: eada51aff9f213a0e08b6ebe8c84cc81961f4fd82a6824d656bac1ab5d78db33