GEN003607 M6 - The system must not accept source-routed IPv4 packets - 'net.inet.ip.accept_sourceroute:0'

Information

Source-routed packets allow the source of the packet to suggest routers forward the packet along a different path than configured on the router, which can be used to bypass network security measures. This requirement applies only to the handling of source-routed traffic destined to the system itself, not to traffic forwarded by the system to another, such as when IPv4 forwarding is enabled and the system is functioning as a router.

Solution

Open a terminal session and edit the /etc/sysctl.conf file and add the following line.

net.inet.ip.accept_sourceroute=0

NOTE- If the sysctl.conf file does not exist use the following command to create one.
touch /etc/sysctl.conf

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CAT|II, CCI|CCI-001551, CSCv6|9.2, Rule-ID|SV-38203r1_rule, STIG-ID|GEN003607-M6, Vuln-ID|V-22414

Plugin: Unix

Control ID: 2f1d898e28138a8ec9926fed5697ed218d6353a63ee39f542c458d4fe02646d9