GEN003605 - The system must not apply reversed source routing to TCP responses.

Information

Source-routed packets allow the source of the packet to suggest routers forward the packet along a different path than configured on the router, which can be used to bypass network security measures.

Solution

Configure the system to not apply reverse source routing to TCP responses to source-routed packets.
# /usr/sbin/no -po nonlocsrcroute=0

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R13_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, CCI|CCI-001551, Group-ID|V-22412, Rule-ID|SV-38799r2_rule, STIG-ID|GEN003605

Plugin: Unix

Control ID: b615dea301d923bc97775bfa742a682697b317685cff15934a8ac074d97c8298