GEN007860 - The system must ignore IPv6 Internet Control Message Protocol (ICMP ) redirect messages

Information

ICMP redirect messages are used by routers to inform hosts of a more direct route existing for a particular destination. These messages modify the host's route table and are unauthenticated. An illicit ICMP redirect message could result in a man-in-the-middle attack.

Solution

Add an IPF rule to block inbound IPv6 ICMP redirect packets.

Edit /etc/opt/ipf/ipf6.conf and add a rule such as:
block in quick proto icmpv6 from any to any icmpv6-type 137

Reload the IPF rules.
# ipf -6 -Fa -A -f /etc/opt/ipf/ipf6.conf

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, CCI|CCI-001551, CSCv6|9.2, Rule-ID|SV-35241r1_rule, STIG-ID|GEN007860, Vuln-ID|V-22550

Plugin: Unix

Control ID: 33de3c07b73463e20573ba2c90cc1f29aacafb7f160260690b3eac72c8a3008e