GEN003610 M6 - The system must not send IPv4 ICMP redirects - 'net.inet.ip.redirect:0'

Information

ICMP redirect messages are used by routers to inform hosts of a more direct route existing for a particular destination. These messages contain information from the system's route table possibly revealing portions of the network topology.

Solution

Open a terminal session and edit the /etc/sysctl.conf file and add the following line.

net.inet.ip.redirect=0

NOTE- If the sysctl.conf file does not exist use the following command to create one.
touch /etc/sysctl.conf

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, CCI|CCI-001551, CSCv6|9.2, Rule-ID|SV-38205r1_rule, STIG-ID|GEN003610-M6, Vuln-ID|V-22417

Plugin: Unix

Control ID: 7075edf76a1b13a1324066e47478105e8a3fa60420b769f46a47cfd08b7504c7