AOSX-13-001206 - The macOS system must not have IP forwarding for IPv6 enabled.

Information

IP forwarding for IPv6 must not be enabled, as only authorized systems should be permitted to operate as routers.

Solution

To configure the system to disable 'IP forwarding', add the following line to '/etc/sysctl.conf', creating the file if necessary:

net.inet6.ip6.forwarding=0

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_OS_X_10-13_V2R5_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-214912r609363_rule, STIG-ID|AOSX-13-001206, STIG-Legacy|SV-96417, STIG-Legacy|V-81703, Vuln-ID|V-214912

Plugin: Unix

Control ID: d0b87140dd3b3cb66b58658de39f2bf25f4e35f28383ddaf001e15799d24dbd6