GEN003605 - The system must not apply reversed source routing to TCP responses

Information

Source-routed packets allow the source of the packet to suggest routers forward the packet along a different path than configured on the router, which can be used to bypass network security measures.

Solution

Disable the IP source-routed forwarding feature.
# ndd -set /dev/ip ip_forward_src_routed 0

Edit /etc/rc.config.d/nddconf and add/set:
TRANSPORT_NAME[x] = ip
NDD_NAME[x] = ip_forward_src_routed
NDD_VALUE[x] = 0

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, CCI|CCI-001551, CSCv6|9.2, Rule-ID|SV-35028r1_rule, STIG-ID|GEN003605, Vuln-ID|V-22412

Plugin: Unix

Control ID: 9dc2ff6420e7beec2700f07b4b99ede2d8d259823322848145b2a0eb0a8dd998