AOSX-13-001205 - The macOS system must not have IP forwarding for IPv4 enabled.

Information

IP forwarding for IPv4 must not be enabled, as only authorized systems should be permitted to operate as routers.

Solution

To configure the system to disable 'IP forwarding', add the following line to '/etc/sysctl.conf', creating the file if necessary:

net.inet.ip.forwarding=0

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_OS_X_10-13_V2R5_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-214911r609363_rule, STIG-ID|AOSX-13-001205, STIG-Legacy|SV-96415, STIG-Legacy|V-81701, Vuln-ID|V-214911

Plugin: Unix

Control ID: 3ebd696b5c9639ebebc40325b662da7246168ff196aabf4afc19be7b780d21e6