NET0770 - IP Source Routing is not disabled on all routers.

Information

The router must have IP source routing disabled.

Source routing is a feature of IP, whereby individual packets can specify routes. This feature is used in several different network attacks by bypassing perimeter and internal defense mechanisms.

Solution

Configure the router to disable IP source routing.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, Rule-ID|SV-15316r2_rule, STIG-ID|NET0770, Vuln-ID|V-3081

Plugin: Cisco

Control ID: c8c5e23735979d70c4905650c94b61baad3e4b305e3b67c127bb04e30b0f44e8