GEN003606 M6 - The system must prevent local applications from generating source-routed packets - 'net.inet.ip.sourceroute:0'

Information

Source-routed packets allow the source of the packet to suggest routers forward the packet along a different path than configured on the router, which can be used to bypass network security measures.

Solution

Open a terminal session and edit the /etc/sysctl.conf file and add the following line.

net.inet.ip.sourceroute=0

NOTE- If the sysctl.conf file does not exist use the following command to create one.
touch /etc/sysctl.conf

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, CCI|CCI-001551, CSCv6|9.2, Rule-ID|SV-38202r1_rule, STIG-ID|GEN003606-M6, Vuln-ID|V-22413

Plugin: Unix

Control ID: 20d06fb54b193d07f2e0100be4deccc903ca40602afc4f1894225c60cabd2911