GEN007920 - The system must not forward IPv6 source-routed packets

Information

Source-routed packets allow the source of the packet to suggest routers forward the packet along a different path than configured on the router, which can be used to bypass network security measures. This requirement applies only to the forwarding of source-routed traffic, such as when IPv6 forwarding is enabled and the system is functioning as a router.

Solution

Configure the system to not forward IPv6 source-routed packets.
# ndd -set /dev/ip6 ip6_forwarding 0

This command should also be added to the ndd configuration file and/or to the system startup script /etc/rc.config.d/nddconf :

TRANSPORT_NAME[index]=ip6
NDD_NAME[index]=ip6_forwarding
NDD_VALUE[index]=0

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, CCI|CCI-001551, CSCv6|9.2, Rule-ID|SV-38378r1_rule, STIG-ID|GEN007920, Vuln-ID|V-22553

Plugin: Unix

Control ID: 2f2cdbd8c35f02ae3e6569f62d20c8d85d2ba27d70abfdb2e68d873ea40f8ee3