GEN003619 - The system must not be configured for network bridging.

Information

Some systems have the ability to bridge or switch frames (link-layer forwarding) between multiple interfaces. This can be useful in a variety of situations but, if enabled when not needed, has the potential to bypass network partitioning and security.

Solution

Configure the system to not use bridging.
# rmmod bridge
Edit /etc/modprobe.conf and add a line such as 'install bridge /bin/false' to prevent the loading of the bridge module.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-001551, CSCv6|9.1, Rule-ID|SV-64213r1_rule, STIG-ID|GEN003619, Vuln-ID|V-22421

Plugin: Unix

Control ID: 8689b02b529dd2c8d3d67a13c3756c60974c317fb93f17327a6aa2f46a539c16