NET0912 - Outbound ICMP messages are not blocked - 'deny icmp any any log'

Information

Internet Control Message Types (ICMP) must be blocked outbound to external untrusted networks (e.g., ISP and other non-DoD networks).

Using ICMP messages for information gathering is a process allowing malicious computer attackers to launch attacks against a targeted network. In this stage the malicious attacker will try to determine what the characteristics of the targeted network. Techniques, such as host detection, service detection, network topology mapping, and operating system fingerprinting are often used. The data collected will be used to identify those hosts running network services, which may have a known vulnerability. This vulnerability may allow the malicious attacker to exploit vulnerabilities in the network or gain unauthorized access to those systems. This unauthorized access may become the focal point to the whole targeted network.

NOTE: Change 'INTERNAL_EGRESS_ACL' to the access-list IP standard access list number for your organization.

Solution

Configure ACLs on network devices to block outbound ICMP messages. Exceptions to this rule are listed below.

Exceptions-

ICMP messages Packet-too-Big (type 3, code 4)
Source Quench (type 4)
Echo Request (type 8)

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, Rule-ID|SV-3027r2_rule, STIG-ID|NET0912, Vuln-ID|V-3027

Plugin: Cisco

Control ID: 0d8beefa53e7aa744dd7a7eabf02d58edebfb9508b288f5e8547e537b27ea893