GEN003609 M6 - The system must ignore IPv4 ICMP redirect messages - 'net.inet.icmp.drop_redirect:0'

Information

ICMP redirect messages are used by routers to inform hosts of a more direct route existing for a particular destination. These messages modify the host's route table and are unauthenticated. An illicit ICMP redirect message could result in a man-in-the-middle attack.

Solution

Open a terminal session and edit the /etc/sysctl.conf file and add the following line.

net.inet.icmp.drop_redirect=0

NOTE- If the sysctl.conf file does not exist use the following command to create one.
touch /etc/sysctl.conf

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(16), CAT|II, CCI|CCI-001503, Rule-ID|SV-38204r1_rule, STIG-ID|GEN003609-M6, Vuln-ID|V-22416

Plugin: Unix

Control ID: 50c773092af60c6ab45c5411deec45144db8daf488f0290e20c22b9f92afd1ca