GEN007820 - The system must not have IP tunnels configured - '/sbin/ip -6 tun list'

Information

IP tunneling mechanisms can be used to bypass network filtering.

Solution

Remove the tunnels.
# ip tun del <tunnel>
Edit system startup scripts to prevent tunnel creation on startup.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R17_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, CCI|CCI-001551, CSCv6|3.1, Group-ID|V-22547, Rule-ID|SV-37613r1_rule, STIG-ID|GEN007820

Plugin: Unix

Control ID: 7da4ad4d1f6ac5f8385b7004c3a0915ff9deceaaf094c39519a1d37d2ba9b1a9